Key takeaways

  • CVE‑2026‑31431 – local‑privilege escalation (LPE) in the Linux kernel, CVSS 7.8.
  • Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on 2026‑05‑01; remediation due 2026‑05‑15.
  • Public exploit code released — works across virtually all major distributions released since 2017.
  • Patches landed in kernel versions 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, 5.10.254.
  • Immediate actions: apply vendor patches, audit for exploit artifacts, enforce kernel hardening controls.

—

Overview of the KEV Addition

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Friday that it has added CVE‑2026‑31431 to its Known Exploited Vulnerabilities (KEV) catalog, citing “evidence of active exploitation in the wild” (The Hacker News). The listing, dated 2026‑05‑01 with a remediation deadline of 2026‑05‑15, signals that the flaw has moved from research‑only to operational use.

CISA’s KEV catalog is a curated feed used by federal agencies and downstream organizations to prioritize patching. Inclusion means that attackers are not just capable of exploiting the bug—they are doing so at scale.

—

What is CVE‑2026‑31431?

  • Vulnerability type: Local privilege escalation (LPE) in the Linux kernel’s cryptographic subsystem, dubbed “Copy Fail.”
  • CWE: CWE‑699 (Incorrect Resource Transfer Between Spheres).
  • CVSS v3.1 base score: 7.8 (high).
  • Affected kernel releases: The flaw exists in every kernel version released since 2017 and is mitigated in the patched releases listed above.
  • Mechanics (publicly disclosed): An unprivileged user can perform a controlled 4‑byte write into the page cache of any readable file, enabling arbitrary modification of set‑uid binaries and thus root escalation (SesameDisk).

—

Exploitation in the Wild

  • Public exploit release: Researchers from Theori published a 732‑byte script on Wednesday (late April 2026) that reliably escalates privileges on all vulnerable distributions (Ars Technica).
  • Scope: The exploit works “with no modification” across major distros, allowing attackers to break out of containers, compromise multi‑tenant systems, and inject malicious code into CI/CD pipelines.
  • Threat‑actor attribution: No specific group has been publicly linked; the KEV entry notes “Known To Be Used in Ransomware Campaigns? Unknown.”
  • Observed payloads: Public sources have not disclosed concrete payload hashes or ransomware families tied to the bug (pending verification).

—

MITRE ATT&CK Mapping

ATT&CK Technique Phase Relevance to CVE‑2026‑31431
T1068 – Exploitation for Privilege Escalation Initial Access / Privilege Escalation Attackers run the public exploit to gain root on a compromised Linux host.
T1021.004 – SSH Lateral Movement Post‑escalation, adversaries often use SSH with stolen keys to pivot to other hosts.
T1087 – Account Discovery (optional) Credential Access Root access enables enumeration of local accounts and credential dumping.

Our read: The bug sits at the privilege‑escalation pivot point, turning any foothold (e.g., compromised web app, container escape) into full system control. Subsequent lateral movement typically follows the SSH path because many Linux environments expose SSH for admin access.

—

High‑Value Targets

  • Cloud workloads running on Linux VMs or containers (AWS, Azure, GCP).
  • Kubernetes clusters where node kernels are shared across pods.
  • CI/CD pipelines that execute untrusted code on shared runners.
  • On‑premises data‑center servers hosting legacy services still on older kernels.

Ripple Effects

  1. Container breakout: A compromised container can modify the host kernel page cache, escaping isolation.
  2. Supply‑chain risk: Malicious pull requests can embed the exploit script into build pipelines, propagating to downstream images.
  3. Service disruption: Root compromise may lead to ransomware encryption or data exfiltration, though no ransomware linkage is confirmed.

—

Indicators of Compromise (IOCs)

  • No publicly released file‑hash or network‑signature IOCs have been disclosed by CISA or researchers at the time of writing (pending verification).
  • Behavioral signs to monitor:
  • Unexpected execution of short (≈ 700 B) scripts by non‑privileged users.
  • Sudden modification timestamps on set‑uid binaries (e.g., /usr/bin/sudo).
  • Unusual ptrace or process_vm_writev syscalls from low‑privilege processes.

Patch Management Timeline

Distribution Patched Kernel Version Release Date (approx.)
Upstream Linux 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, 5.10.254 2026‑04‑01 (mainline commit) (Ars Technica)
Debian/Ubuntu Kernel ≥ 6.1.170 (released in security update) 2026‑04‑15 (security advisory)
Red Hat Enterprise Linux (RHEL) Kernel ≥ 6.6.137 (RHSA‑2026:xxxx) 2026‑04‑20
SUSE Linux Enterprise Server (SLES) Kernel ≥ 5.15.204 2026‑04‑22

Our read: Organizations should verify the exact kernel version running on each host and apply the earliest patch that includes the fix. If a vendor has not yet released an update, CISA advises “apply mitigations per vendor instructions, follow applicable BOD 22‑01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable” (CISA KEV entry).

Hardening Controls

  • Enable SELinux/AppArmor enforcing mode to limit arbitrary writes to the page cache.
  • Restrict ptrace via /proc/sys/kernel/yama/ptrace_scope = 2.
  • Audit execve for short scripts executed by non‑root users (auditctl -a exit,always -F arch=b64 -S execve -F uid>=1000 -F exe=/usr/bin/python3).
  • Network segmentation: isolate SSH access to bastion hosts; enforce MFA for privileged accounts.

—

Patch Availability by Distribution

Vendor Patch Version Advisory Link
Linux kernel maintainers 7.0, 6.19.12, … (see commit list) Linux‑CVE‑announce
Debian 6.1.170‑1 (pending verification)
Red Hat 6.6.137‑1.el8 (pending verification)
SUSE 5.15.204‑1 (pending verification)

Our read: The upstream kernel fix was merged on 2026‑04‑01; most major distros have issued patches within the following weeks. However, the rapid public exploit release left a window where many systems remained vulnerable.

Public‑Facing Advisory Coordination

CISA’s KEV entry references coordination with NIST and CERT‑US, indicating that the vulnerability was added to multiple national advisories simultaneously. The joint effort underscores the cross‑agency priority placed on this Linux flaw.

—

What We Don’t Yet Know

  • Attacker motivation: Whether the bug is being weaponized for espionage, ransomware, or cryptomining remains unclear.
  • Scope of compromise: No definitive count of infected systems has been disclosed.
  • Zero‑day variants: It is unknown if additional, related kernel bugs are being chained with CVE‑2026‑31431.
  • Ransomware linkage: The KEV entry lists “Known To Be Used in Ransomware Campaigns? Unknown.”

—

FAQ

  1. What systems are vulnerable to CVE‑2026‑31431?
  2. All Linux kernels released since 2017 are vulnerable unless patched to one of the versions listed above. This includes most server, cloud, and container hosts.

  1. How can I verify if my Linux host has been exploited?
  2. Look for unexpected modifications of set‑uid binaries, short‑lived scripts executed by non‑root users, and anomalous ptrace or process_vm_writev syscalls. Use auditd or a SIEM to surface these behaviors.

  1. Do container images inherit the vulnerability?
  2. Yes. Containers share the host kernel; a compromised host kernel can be abused from within any container, and a container‑borne exploit can affect the host if the kernel is unpatched.

  1. Is there a known ransomware payload linked to this bug?
  2. No ransomware payload has been publicly tied to CVE‑2026‑31431; the KEV entry lists the ransomware link as “Unknown.”

  1. When will the next CISA KEV update be released?
  2. CISA updates the KEV catalog on a rolling basis; the schedule is not fixed. Organizations should monitor the CISA KEV page for new entries.

—

Conclusion

CISA’s addition of CVE‑2026‑31431 to the KEV catalog marks a clear escalation from research to active threat. The public exploit, its cross‑distribution reach, and the short remediation window make rapid patching essential. Administrators should verify kernel versions, apply vendor patches immediately, and enable hardening controls while monitoring for the behavioral IOCs described above.

What to watch next:

  • Additional advisories from NIST and vendor security teams.
  • Emerging IOCs or ransomware variants that may start leveraging the bug.
  • Updates to CISA’s KEV list indicating broader exploitation.

—

Sources