oss-sec mailing list archives
Re: CVE-2026-31431: CopyFail: linux local privilege scalation
From: Salvatore Bonaccorso <carnil () debian org>
Date: Thu, 30 Apr 2026 09:01:22 +0200
Hi, On Thu, Apr 30, 2026 at 05:52:37AM +0100, Sam James wrote:
Eddie Chapman <eddie () ehuk net> writes:On 29/04/2026 21:23, Jan Schaumann wrote:Affected and fixed versions =========================== Issue introduced in 4.14 with commit 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in 6.18.22 with commit fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 Issue introduced in 4.14 with commit 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in 6.19.12 with commit ce42ee423e58dffa5ec03524054c9d8bfd4f6237 Issue introduced in 4.14 with commit 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in 7.0 with commit a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237 https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5So this is one of the worst make-me-root vulnerabilities in the kernel in recent times. I see that on the 11th of April 6.19.12 & 6.18.22 were released with the fix backported. Longterm 6.12, 6.6, 6.1, 5.15, 5.10 have not received the fix and I don't see anything in the upstream stable queues yet as I write. My guess is backporting that far back is not as straightforward. As this was introduced in 2017 all those older kernels are affected, right? Or am I missing something?It does not apply cleanly, no. Attached is the workaround we're going to use. I'm not an expert on IPSec but I think this is the lesser evil. I attempted a backport but ran into a few API changes and wasn't confident enough to muck around with it, especially for something to deploy immediately.
Backports have just been posted, for 6.12.y: https://lore.kernel.org/stable/2026043038-unwilling-slogan-a20e@gregkh/T/#t (but I do not see them yet for all versions, but guess following soon) Regards, Salvatore
Current thread:
- CVE-2026-31431: CopyFail: linux local privilege scalation Jan Schaumann (Apr 29)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Eddie Chapman (Apr 29)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Sam James (Apr 29)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Salvatore Bonaccorso (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Greg KH (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation cyber security (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Greg KH (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Solar Designer (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Greg KH (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Sam James (Apr 29)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Alan Coopersmith (Apr 30)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Reid Sutherland (May 01)
- Re: [EXTERNAL] Re: [oss-security] CVE-2026-31431: CopyFail: linux local privilege scalation Shrader, David Lee (May 01)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Justin Swartz (May 01)
- Re: Re: CVE-2026-31431: CopyFail: linux local privilege scalation cyber security (May 01)
- Re: CVE-2026-31431: CopyFail: linux local privilege scalation Eddie Chapman (Apr 29)
