Post #2491127
2026-05-04 09:30 UTC
https://security-tracker.debian.org/tracker/CVE-2026-31431
« In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. »
#cve #debian #cybersecurity
Replies (1)
-
@ronan@mastodon.ronandev.ovh 2026-05-04 17:27
"Copy Fail" (CVE-2026-31431) Un utilisateur local sans privilège peut écrire 4 bytes contrôlés dans le cache de TOUT fichier lisible ➡️ élévation root. Si vous avez du multi-tenant, des conteneurs, des CI runners non fiables ➡️ mettez à jour. Ordinateur perso ➡️ moins urgent mais mettez à jour quand même. L'article : https://xint.io/blog/copy-fail-linux-distributions (en) Le site : https://copy.fail/ (en) #linux #cybersecurity