CVE-2026-31431
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Description
CVE-2026-31431 is a HIGH severity local privilege escalation vulnerability in the Linux kernel's algif_aead AF_ALG socket interface, with a CVSS 3.1 score of 7.8. The flaw — publicly known as "copy_fail" — stems from a kernel commit that introduced in-place operation in algif_aead, allowing a local user with access to the AEAD socket interface to manipulate the page cache and corrupt memory in a way that yields root privileges. The fix reverts the original commit and forces out-of-place operation, copying associated data instead of mapping it in place. CISA added CVE-2026-31431 to the KEV catalog on May 1, 2026, with an aggressive remediation deadline of May 15, 2026. Public exploit code is available from theori-io ("copy_fail"), and detailed write-ups have been published on websec.net and copy.fail. The EPSS score of 0.040 (88th percentile) reflects high relative likelihood of continued exploitation.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| linux | linux kernel | >= 4.14, < 5.10.254; >= 5.11, < 5.15.204; >= 5.16, < 6.1.170; >= 6.2, < 6.6.137; >= 6.7, < 6.12.85; >= 6.13, < 6.18.22; >= 6.19, < 6.19.12; 7.0 |
| redhat | openshift container platform | >= 4.12, < 4.12.89; >= 4.13, < 4.13.66; >= 4.14, < 4.14.65; >= 4.15, < 4.15.64; >= 4.16, < 4.16.61; >= 4.17, < 4.17.53; >= 4.18, < 4.18.40; >= 4.19, < 4.19.30; >= 4.20, < 4.20.21; >= 4.21, < 4.21.14; 4.0 |
| redhat | enterprise linux | 8.0; 9.0; 10.0 |
| redhat | enterprise linux aus | 8.4; 8.6 |
| redhat | enterprise linux eus | 8.4; 9.4; 9.6; 10.0 |
| redhat | enterprise linux tus | 8.6; 8.8 |
| redhat | enterprise linux update services for sap solutions | 8.6; 8.8; 9.0; 9.2 |
| amazon | amazon linux | - |
| canonical | ubuntu linux | -; 14.04; 16.04; 18.04; 20.04; 22.04; 24.04; 25.10 |
| debian | debian linux | 11.0; 12.0; 13.0 |
| opensuse | leap | 15.3; 15.4; 15.5; 15.6 |
| suse | caas platform | 4.0 |
| suse | enterprise storage | 6.0; 7.0; 7.1 |
| suse | manager proxy | 4.0; 4.1; 4.2; 4.3 |
| suse | manager retail branch server | 4.0; 4.1; 4.2; 4.3 |
| suse | manager server | 4.0; 4.1; 4.2; 4.3 |
| suse | openstack cloud | 9.0 |
| suse | openstack cloud crowbar | 9.0 |
| suse | basesystem module | 15 |
| suse | development tools module | 15 |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c(Patch)
- https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc(Patch)
- https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667(Patch)
- https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82(Patch)
- https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b(Patch)
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5(Patch)
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237(Patch)
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8(Patch)
- http://www.openwall.com/lists/oss-security/2026/04/29/23(Exploit, Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/29/25(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/29/26(Exploit, Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/10(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/11(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/12(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/14(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/15(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/16(Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/17(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/04/30/18(Exploit, Mailing List)
- http://www.openwall.com/lists/oss-security/2026/04/30/2(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/04/30/20(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/04/30/5(Exploit, Mailing List, Patch)
- http://www.openwall.com/lists/oss-security/2026/04/30/6(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/10(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/12(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/15(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/16(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/17(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/18(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/2(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/22(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/23(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/24(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/01/3(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/14(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/15(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/16(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/17(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/18(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/19(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/20(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/21(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/23(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/24(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/25(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/4(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/5(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/6(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/7(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/02/8(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/10(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/12(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/13(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/3(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/4(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/5(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/03/6(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/1(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/10(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/11(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/12(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/13(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/14(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/2(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/24(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/27(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/28(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/29(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/31(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/8(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/04/9(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/06/5(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/07/12(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/07/2(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/08/13(Mailing List)
- http://www.openwall.com/lists/oss-security/2026/05/18/3(Mailing List)
- https://copy.fail(Exploit)
- https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170(Exploit, Third Party Advisory)
- https://www.kb.cert.org/vuls/id/260001(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13565(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13566(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13577(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13578(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13681(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13690(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13727(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13729(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13734(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13811(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13862(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13885(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13887(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13932(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:13936(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14097(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14112(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14137(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14165(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14230(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14301(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14339(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14773(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:14926(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:15087(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:15976(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:15978(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:16018(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:16063(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:16111(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:16208(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:16209(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:16210(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:19074(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:19225(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2026:33486(Third Party Advisory)
- https://access.redhat.com/security/cve/CVE-2026-31431(Third Party Advisory)
- https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigation(Third Party Advisory)
- https://bugzilla.redhat.com/show_bug.cgi?id=2460538(Issue Tracking, Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html(Third Party Advisory)
- https://github.com/theori-io/copy-fail-CVE-2026-31431(Exploit)
- https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/(Vendor Advisory)
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31431.json(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431(US Government Resource)
- https://xint.io/blog/copy-fail-linux-distributions#the-fix-6(Exploit, Patch, Third Party Advisory)
Weakness Type
CWE-669: Incorrect Resource Transfer Between Spheres
Incorrect Resource Transfer Between Spheres occurs when a product transfers a resource to another sphere in a way that violates the intended security boundaries — for example, transferring sensitive data to untrusted contexts or importing untrusted data into a privileged sphere. In CVE-2026-31431, the Linux kernel's algif_aead socket implementation transferred user-supplied page mappings into the kernel's cryptographic processing path in a way that conflated the user's source pages with the kernel's destination pages (in-place operation). Because the source and destination came from different mappings, the in-place optimization broke the security boundary between userspace and kernel-managed page cache memory, and a local attacker could leverage the mishandling to write attacker-controlled data into pages that the kernel later treats as trusted — escalating from a low-privileged local user to root.
Learn more: CWE-669 — Incorrect Resource Transfer Between Spheres
Impact Analysis
CVE-2026-31431 carries a CVSS 3.1 score of 7.8 (HIGH) with the vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — local attack vector with low complexity, only low privileges required (any user account that can call socket(AF_ALG)), no user interaction needed, and uniformly High impact across Confidentiality, Integrity, and Availability. The local attack vector is sometimes underestimated, but for multi-tenant Linux systems the impact is severe: containers, shared web hosts, CI runners, and developer machines that grant remote shell access to untrusted code all expose the AF_ALG interface to the attacker. Successful exploitation yields kernel-level code execution and full root privileges on the host, which on a containerized system means container escape, and on a hypervisor-host means tenant compromise. Because the bug is in the Linux kernel itself, the vulnerable code is shipped in essentially every major distribution running affected kernel versions, and the long range of affected versions (4.14 through 6.19.11) means that even slow-moving enterprise distributions are likely vulnerable until they pull the backported fix.
Exploit Maturity
Public Exploits: Multiple public proofs-of-concept and weaponized exploits exist for CVE-2026-31431. The theori-io research team has published a working exploit at github.com/theori-io/copy-fail-CVE-2026-31431; an in-depth technical write-up titled "copy_fail: Linux algif_aead page cache write to root" is available on websec.net; and a dedicated landing page at copy.fail documents the discovery. The OSS-Security mailing list has published more than 30 follow-up posts including additional exploit details and discussion. Active Exploitation: CISA confirmed in-the-wild exploitation by adding CVE-2026-31431 to the KEV catalog on May 1, 2026, with a remediation deadline of May 15, 2026. Exploitation Probability: With an EPSS score of 0.040 (88th percentile), the model rates the probability of continued exploitation as elevated — typical for kernel privilege-escalation bugs whose primary use is post-compromise escalation rather than mass internet scanning. Practical Risk: Operators of multi-tenant Linux environments — public clouds, container platforms, shared web hosts, CI/CD systems — should treat this vulnerability as a top-priority remediation, since a single low-privileged tenant can pivot to full host root.
Remediation
- Apply the upstream Linux kernel patch. Update to a kernel that includes the revert of the in-place
algif_aeadoperation: 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, or 7.0+. The official patches are tracked at kernel.org and Red Hat's customer guidance is at access.redhat.com. - Apply your distribution's security update. Pull the patched kernel package from your distro security feed (Debian/Ubuntu, RHEL/CentOS Stream, SUSE, Amazon Linux, etc.) and reboot. For long-running multi-tenant hosts, consider live-patching where supported (kpatch, kgraft, ksplice, livepatch).
- Interim mitigation: disable AF_ALG access. Where the patch cannot be applied immediately, restrict access to the AF_ALG socket interface. On systems that do not require userspace AEAD via algif, disable the
algif_aeadandaf_algmodules (rmmod algif_aead af_alg) and prevent reload viamodprobe.d. In containerized environments, drop the relevant kernel capabilities and apply seccomp profiles that blocksocket(AF_ALG, ...). - Hunt for prior exploitation. Review kernel and audit logs for unexpected privilege-escalation events around the disclosure window (April 22–May 4, 2026). Check
/var/log/audit/audit.logfor setuid transitions to root from non-privileged users, look for unexpecteddmesgentries from thealgif_aeadsubsystem, and review container-runtime logs for capability-set changes. - Long-term hardening. Apply the CWE-669 principle by minimizing kernel attack surface exposed to untrusted local code: use seccomp/Landlock to restrict syscalls, deploy unprivileged user namespaces, and consider kernel hardening features (kernel module loading lockdown, SECCOMP_FILTER, AppArmor or SELinux profiles) to reduce the practical exploitability of similar future bugs.
Technical Details
CVE-2026-31431 is a CWE-669 incorrect-resource-transfer flaw in the Linux kernel's algif_aead module, the userspace interface to the kernel's authenticated-encryption (AEAD) crypto API exposed via AF_ALG sockets. The vulnerability was introduced by commit 72548b093ee3, which converted algif_aead to operate in place on the user-supplied source pages instead of copying the data out-of-place to a kernel-allocated destination. Because the AF_ALG source and destination buffers come from different mappings, the in-place optimization causes the kernel to treat user-mapped page cache memory as the target of crypto output, allowing a carefully crafted sequence of socket operations to write attacker-controlled bytes into pages that other parts of the kernel (or other processes) treat as trusted. The published "copy_fail" exploit chains this primitive into a page-cache-to-root escalation: by selecting target pages backing a setuid-root binary or a privileged kernel data structure, the attacker overwrites them with malicious content and triggers execution as root. The CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H reflects the local nature of the attack and its uniformly High impact. The fix reverts most of the in-place commit while retaining the copy of associated data — eliminating the conflation of user and kernel page mappings.
Frequently Asked Questions
Is CVE-2026-31431 being actively exploited?
Yes. CISA added CVE-2026-31431 to the KEV catalog on May 1, 2026, with a 14-day remediation deadline of May 15, 2026. Public exploit code is available from theori-io and websec.net, and the OSS-Security mailing list has documented active discussion since April 29, 2026. The EPSS score of 0.040 (88th percentile) reflects elevated continued exploitation likelihood.
What products are affected by CVE-2026-31431?
The upstream Linux kernel from version 4.14 through 6.19.11 (and version 7.0 prior to the fix) is vulnerable. Patched kernels: 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, and 7.0+. Every major Linux distribution shipping a kernel in this range is affected until it pulls the backport.
How do I fix CVE-2026-31431?
Update to a patched upstream kernel or your distribution's security release and reboot (or apply a live-patch where supported). Where patching is delayed, restrict access to the AF_ALG socket interface — disable algif_aead/af_alg kernel modules or use seccomp/AppArmor/SELinux profiles to block socket(AF_ALG, ...) for untrusted code.
How severe is CVE-2026-31431?
CVE-2026-31431 is rated HIGH (CVSS 3.1 score 7.8) with full High impact on Confidentiality, Integrity, and Availability. While the local attack vector limits remote exploitability, multi-tenant Linux environments (cloud, containers, shared hosting, CI runners) should treat it as a critical-priority remediation because any local user can escalate to root, breaking tenant isolation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.