Elektrine lite

← Feed

@jschauma@mstdn.social

Post #2173030

2026-05-02 13:44 UTC

Alma - https://almalinux.org/blog/2026-05-01-cve-2026-31431-copy-fail/ fixed Alpine - https://security.alpinelinux.org/vuln/CVE-2026-31431 fixed (per https://fosstodon.org/@alpinelinux/116500119563494081) Arch - https://security.archlinux.org/CVE-2026-31431 https://security.archlinux.org/AVG-2908 fixed in linux 6.19.12-1 Centos - pending RedHat: https://bugzilla.redhat.com/show_bug.cgi?id=2460538 ? Debian - https://security-tracker.debian.org/tracker/CVE-2026-31431 13 (Trixie), 12 (bookworm), 11 (bullseye) all still vulnerable, but fixed in security releases #copyfail

Replies (4)

  • @jschauma@mstdn.social 2026-05-02 13:44

    Fedora - https://bugzilla.redhat.com/show_bug.cgi?id=2460538 "For any Fedora users finding a link here: this was fixed in kernel 6.19.12, and all current Fedora branches are already at or past that version." Gentoo - https://bugs.gentoo.org/973385 Kali - should have it by tracking Debian security Suse / OpenSuse etc. - https://www.suse.com/security/cve/CVE-2026-31431.html RedHat - https://access.redhat.com/security/cve/cve-2026-31431 relevant for various downstreams #copyfail

    Open ##2173031

  • @lnl@screaminginsi.de 2026-05-02 13:46

    @jschauma indeed doesn't appear on secdb (didn't know there was a CVE number) but it is fixed in Alpine https://fosstodon.org/@alpinelinux/116500119563494081

    Open ##2173068

  • @grabbi_it@defcon.social 2026-05-02 14:53

    @jschauma oh it would be great to update the gazillions base images of containers out there based on Alpine….

    Open ##2173069

  • @edmonds@infosec.exchange 2026-05-02 18:43

    @jschauma > 13 (Trixie), 12 (bookworm), 11 (bullseye) all still vulnerable, but fixed in security releases No, these releases have all been fixed. The red lines on the security tracker pages are indicating that the latest package version available in the install media archives is still vulnerable. In Debian, the latest stable security update packages are made available via a first-party security mirror network, which is separate from the larger third-party mirror network that most packages are distributed from. This mitigates against a malicious third-party mirror operator withholding security updates. When a stable point release update is prepared (e.g. the most recent was Debian 13.4, on March 14, 2026), all the security fixes released via the security archive, as well as other stable package updates, are copied into the base repository and installation media are refreshed. Then the red lines on the security tracker pages will disappear. You could in theory install Debian off old install media and disable the security archive in your apt sources configuration. But that would be insane, that would be like installing Windows 11 off of a DVD and disabling Windows Update, and it would similarly be incorrect to say that Windows 11 is vulnerable to something because a fix is only available via Windows Update and the fix is not present on the latest DVD install image.

    Open ##2173070