FlawAtlas
Search the atlas
USN-8281-1 Not scored

linux, linux-aws, linux-aws-fips, linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle vulnerabilities

It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Packet sockets; (CVE-2026-31504, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078)

Exploit probability Not scored
Published May 19, 2026
Required by Not available
Last source change July 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:Pro:18.04:LTS linux

149 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-aws

135 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-gcp-4.15

89 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-kvm

127 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-oracle

114 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS linux-aws-fips

90 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS linux-fips

93 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS linux-gcp-fips

65 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-8281-1

It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Packet sockets; (CVE-2026-31504, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078)

View original source

05 / REFERENCES

Further evidence