Copy Fail — Linux kernel algif_aead LPE (ITW, KEV deadline 2026-05-15)
cve · CVE-2026-31431
Coverage timeline
3
first 2026-05-06 → last 2026-05-09
Briefs
3
3 distinct
Sources cited
28
23 hosts
Sections touched
2
active_vulns, updates
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-09CTI Daily Brief — 2026-05-09
- 2026-05-07CTI Daily Brief — 2026-05-07
- 2026-05-06CTI Daily Brief — 2026-05-06
Where this entity is cited
- updates2
- active_vulns1
Source distribution
- access.redhat.com2 (7%)
- helpnetsecurity.com2 (7%)
- microsoft.com2 (7%)
- thehackernews.com2 (7%)
- ubuntu.com2 (7%)
- attack.mitre.org1 (4%)
- bleepingcomputer.com1 (4%)
- cert.europa.eu1 (4%)
- other15 (54%)
External references
All cited sources (28)
- cert.europa.euprimaryinlineCERT-EUROPA advisory 2026-005 update, 2026-05-08https://cert.europa.eu/publications/security-advisories/2026-005/
- access.redhat.cominlineRed Hat security bulletinhttps://access.redhat.com/security/vulnerabilities/RHSB-2026-003
- access.redhat.cominlineRed Hat RHSB-2026-02https://access.redhat.com/security/vulnerabilities/RHSB-2026-02
- attack.mitre.orginlineT1070.002https://attack.mitre.org/techniques/T1070/002/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-05https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/
- cisa.govinlineCISA KEV entry CVE-2026-31431https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- cyberkendra.cominlineCyberKendra, 2026-05-07https://www.cyberkendra.com/2026/05/jdownloader-website-hacked-malicious.html
- cyberscoop.cominlineCyberScoop, 2026-05-05https://cyberscoop.com/cpanel-authentication-bypass-vulnerability-cve-2026-41940-exploited/
- flare.ioinlineFlare.io, 2026-05-07https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
- github.cominlineResearcher write-up (V4bel), 2026-05-07https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md
- helpnetsecurity.cominlineHelp Net Security, 2026-05-04https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-08https://www.helpnetsecurity.com/2026/05/08/dirty-frag-linux-vulnerability-cve-2026-43284-cve-2026-43500/
- labs.watchtowr.cominlinewatchTowr Labshttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-08https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-01https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/
- piunikaweb.cominlinePiunikaWeb, 2026-05-08https://piunikaweb.com/2026/05/08/jdownloader-website-hacked-malware/
- rapid7.cominlineRapid7 ETRhttps://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/
- securelist.cominlineKaspersky Securelist — CVE-2025-68670, 2026-05-08https://securelist.com/cve-2025-68670/119742/
- security-hub.ncsc.admin.chinlineNCSC-CH advisory 12547, 2026-05-08https://security-hub.ncsc.admin.ch/api/posts/12547/details
- securityweek.cominlineSecurityWeek, 2026-05-04https://www.securityweek.com/sophisticated-quasar-linux-rat-targets-software-developers/
- thehackernews.cominlineThe Hacker News, 2026-05-06https://thehackernews.com/2026/05/cisa-adds-actively-exploited-linux-root.html
- thehackernews.cominlineThe Hacker News, 2026-05-08https://thehackernews.com/2026/05/new-linux-pamdoora-backdoor-uses-pam.html
- trendmicro.cominlineTrend Micro Research, 2026-05-04https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.html
- ubuntu.cominlineUbuntu bloghttps://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available
- ubuntu.cominlineUbuntu, 2026-05-01https://ubuntu.com/blog/copy-fail-vulnerability-fixes-available
- unit42.paloaltonetworks.cominlineUnit 42, 2026-05-05https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/
- wid.cert-bund.deinlineBSI CERT-Bund WID-SEC-2026-1232, updated 2026-05-04https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1232
- wiz.ioinlineWiz Research, 2026-05-08https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc
Items in briefs about Copy Fail — Linux kernel algif_aead LPE (ITW, KEV deadline 2026-05-15)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.