FlawAtlas
Search the atlas
USN-8279-1 Not scored

linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux-realtime vulnerabilities

It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Ethernet bonding driver; - SMB network file system; - Netfilter; - io_uring subsystem; - Packet sockets; - TLS protocol; (CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078)

Exploit probability Not scored
Published May 19, 2026
Required by Not available
Last source change August 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS linux

94 explicit affected versions

Ubuntu:22.04:LTS linux-aws

86 explicit affected versions

Ubuntu:22.04:LTS linux-gcp

87 explicit affected versions

Ubuntu:22.04:LTS linux-gke

86 explicit affected versions

Ubuntu:22.04:LTS linux-gkeop

79 explicit affected versions

Ubuntu:22.04:LTS linux-ibm

84 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iotg

74 explicit affected versions

Ubuntu:22.04:LTS linux-kvm

85 explicit affected versions

Ubuntu:22.04:LTS linux-nvidia

71 explicit affected versions

Ubuntu:22.04:LTS linux-nvidia-tegra

44 explicit affected versions

Ubuntu:22.04:LTS linux-oracle

87 explicit affected versions

Ubuntu:22.04:LTS linux-raspi

81 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-aws-5.15

75 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-hwe-5.15

75 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-ibm-5.15

55 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-intel-iotg-5.15

63 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-nvidia-tegra-5.15

33 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS linux-aws-fips

49 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS linux-fips

51 explicit affected versions

Ubuntu:Pro:FIPS-updates:22.04:LTS linux-gcp-fips

46 explicit affected versions

Ubuntu:Pro:Realtime:22.04:LTS linux-realtime

85 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-8279-1

It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Ethernet bonding driver; - SMB network file system; - Netfilter; - io_uring subsystem; - Packet sockets; - TLS protocol; (CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351, CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078)

View original source

05 / REFERENCES

Further evidence