← 목록으로 돌아가기

보안 뉴스 · 취약점

2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

출처
CERT-EU
원문 게시일
마지막 본문 수집
2026. 09. 14. 16:40 KST

출처: CERT-EU · © Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU). · CC BY 4.0
문서 서식과 링크를 FineTS 화면에 맞게 정리했습니다. 이미지·첨부파일은 공식 원문에서 확인하세요.

공식 원문에서 읽기 ↗
기사 원문에 등장한 CVE별 취약점, 설명, 조치사항
취약점설명조치사항
CVE-2026-31431

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

  1. RHSA-2026:14926: NVIDIA for RHEL 10
  2. RHSA-2026:33486: NVIDIA for RHEL 10
  3. RHSA-2026:14097: Red Hat OpenShift Container Platform 4.12
  4. RHSA-2026:14112: Red Hat OpenShift Container Platform 4.13
  5. RHSA-2026:15087: Red Hat OpenShift Container Platform 4.14
  6. RHSA-2026:14773: Red Hat OpenShift Container Platform 4.15
  7. RHSA-2026:13729: Red Hat OpenShift Container Platform 4.16
  8. RHSA-2026:13885: Red Hat OpenShift Container Platform 4.17
  9. RHSA-2026:13727: Red Hat OpenShift Container Platform 4.18
  10. RHSA-2026:13690: Red Hat OpenShift Container Platform 4.19
  11. RHSA-2026:13862: Red Hat OpenShift Container Platform 4.20
  12. RHSA-2026:13811: Red Hat OpenShift Container Platform 4.21
  13. RHSA-2026:13887: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0), Red Hat Enterprise Linux Real Time EUS (v. 10.0), Red Hat Enterprise Linux Real Time for NFV EUS (v. 10.0)
  14. RHSA-2026:13566: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)
  15. RHSA-2026:19074: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10)
  16. RHSA-2026:13936: Red Hat Enterprise Linux AppStream E4S (v.9.0), Red Hat Enterprise Linux BaseOS E4S (v.9.0)
  17. RHSA-2026:13734: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  18. RHSA-2026:13932: Red Hat CodeReady Linux Builder EUS (v.9.4), Red Hat Enterprise Linux AppStream EUS (v.9.4), Red Hat Enterprise Linux BaseOS EUS (v.9.4), Red Hat Enterprise Linux Real Time EUS (v.9.4), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  19. RHSA-2026:14339: Red Hat CodeReady Linux Builder EUS (v.9.6), Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6), Red Hat Enterprise Linux Real Time EUS (v.9.6), Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)
  20. RHSA-2026:13565: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)
  21. RHSA-2026:19225: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9)
  22. RHSA-2026:13577: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8)
  23. RHSA-2026:15976: Red Hat Enterprise Linux BaseOS (v. 8)
  24. RHSA-2026:14165: Red Hat Enterprise Linux BaseOS AUS (v.8.4), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  25. RHSA-2026:14230: Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS E4S (v.8.6), Red Hat Enterprise Linux BaseOS TUS (v.8.6)
  26. RHSA-2026:16111: Red Hat Enterprise Linux BaseOS E4S (v.8.6)
  27. RHSA-2026:13681: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8)
  28. RHSA-2026:16210: Red Hat Enterprise Linux BaseOS E4S (v.8.8)
  29. RHSA-2026:16209: Red Hat Enterprise Linux BaseOS E4S (v.9.0)
  30. RHSA-2026:16208: Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  31. RHSA-2026:16063: Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  32. RHSA-2026:16018: Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  33. RHSA-2026:15978: Red Hat Enterprise Linux BaseOS (v. 9)
  34. RHSA-2026:13578: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8)
  35. RHSA-2026:14137: Red Hat Enterprise Linux NFV E4S (v.9.0), Red Hat Enterprise Linux Real Time E4S (v.9.0)
  36. RHSA-2026:14301: Red Hat Enterprise Linux Real Time E4S (v.9.2), Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
  37. See the security bulletin for a detailed mitigation procedure.

한국어 버튼을 눌러 번역을 요청할 수 있습니다.

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has bee

History:

  • 29/04/2026 --- v1.0 -- Initial publication

Summary

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed [1].

The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.

As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.

Technical Details

The vulnerability CVE-2026-31431, with a CVSS score of 7.8, is a local privilege escalation flaw in the Linux kernel's algif_aead module, the AEAD socket interface of the kernel's userspace crypto API (AF_ALG). The flaw originates from an in-place optimisation introduced in 2017 (commit 72548b093ee3), which allows page-cache pages to be placed into a writable destination scatterlist. By chaining an AF_ALG socket operation with splice(), an unprivileged local user can perform a controlled 4-byte write to an arbitrary page-cache-backed page, targeting a setuid binary such as /usr/bin/su to obtain a root shell [1].

The upstream fix is mainline commit a664bf3d603d, which reverts the 2017 optimisation. It was committed on 1 April 2026 [1].

Affected Products

The vulnerability affects every mainstream Linux distribution shipping a kernel built between 2017 and the availability of the patch. The following distributions were directly verified by the researchers [1]:

표가 화면보다 넓으면 표 안에서 좌우로 스크롤할 수 있습니다.

DistributionKernel Version
Ubuntu 24.04 LTS6.17.0-1007-aws
Amazon Linux 20236.18.8-9.213.amzn2023
RHEL 10.16.12.0-124.45.1.el10_1
SUSE 166.12.0-160000.9-default

Other distributions running kernels in the affected range are implicitly affected, including Debian, Arch Linux, Fedora, Rocky Linux, AlmaLinux, Oracle Linux, and embedded Linux distributions.

Patch availability by distribution (as of 30 April 2026):

표가 화면보다 넓으면 표 안에서 좌우로 스크롤할 수 있습니다.

DistributionStatus
Ubuntu 20.04–24.04No fix available
Amazon Linux 2023No fix available
SUSE Linux EnterpriseNo fix available
Red Hat Enterprise LinuxStatus unknown

Note: Ubuntu 26.04 (Resolute) and later kernels are not affected [2].

Additional information is available in the researcher's advisory [1] and in vendor security trackers [2,3,4].

Recommendations

CERT-EU strongly recommends applying the relevant kernel update as soon as possible once vendor patches become available, prioritising Kubernetes nodes and CI/CD runners.

Temporary Mitigation

Disable the algif_aead kernel module persistently on all affected systems until a patched kernel is available:

echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf     rmmod algif_aead 2>/dev/null || true 

This workaround does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. It may affect applications explicitly configured to use the afalg engine or that bind aead/skcipher/hash sockets directly. Exposure can be assessed with lsof | grep AF_ALG.

Hardening Containerised Environments and Pipelines

CERT-EU recommends blocking AF_ALG socket creation via seccomp policies on all containerised workloads and pipelines, regardless of patch status [1]. This applies to Docker and Podman-based environments [5] as well as Kubernetes clusters [6]. Since the exploit requires opening an AF_ALG socket as a first step, this measure effectively prevents exploitation even on unpatched kernels.

References

[1] https://copy.fail

[2] https://ubuntu.com/security/CVE-2026-31431

[3] https://www.suse.com/security/cve/CVE-2026-31431

[4] https://access.redhat.com/security/cve/CVE-2026-31431

[5] https://docs.docker.com/engine/security/seccomp/

[6] https://kubernetes.io/docs/tutorials/security/seccomp/

공식 원문에서 읽기 ↗

← 목록으로 돌아가기