Elektrine lite

← Feed

@ronan@mastodon.ronandev.ovh

Post #2491127

2026-05-04 09:30 UTC

https://security-tracker.debian.org/tracker/CVE-2026-31431 « In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. » #cve #debian #cybersecurity

Replies (1)

  • @ronan@mastodon.ronandev.ovh 2026-05-04 17:27

    "Copy Fail" (CVE-2026-31431) Un utilisateur local sans privilège peut écrire 4 bytes contrôlés dans le cache de TOUT fichier lisible ➡️ élévation root. Si vous avez du multi-tenant, des conteneurs, des CI runners non fiables ➡️ mettez à jour. Ordinateur perso ➡️ moins urgent mais mettez à jour quand même. L'article : https://xint.io/blog/copy-fail-linux-distributions (en) Le site : https://copy.fail/ (en) #linux #cybersecurity

    Open ##2822108