CVE-2026-31431

7 karet z 12 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-31431

KEV ✓ EPSS 1.00 EPSS k 20. 9. 2026 náprava do 15. 5. 2026

Hodnocení závažnosti

7.8 CVSS 3.1 Linux · redhat-SADP

útok z místního přístupu bez přípravy stačí běžný účet bez zásahu uživatele
dopad plný únik dat úplná změna dat úplný výpadek
přesah dopad jen na zranitelnou součást

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1

CISA Releases Eight Industrial Control Systems Advisories

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.9, CVEs: CVE-2026-13348, CVE-2026-31431, CVE-2026-13336, CVE-2026-13337, CVE-2025-6625, CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941, CVE-2026-15688, CVE-2026-86520, CVE-2026-86689, CVE-2026-77960, CVE-2026-13584, Summary: CISA released eight Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues,…

KEV ✓ EPSS 1.00 CVSS 9.9 CVE-2024-3980 CVE-2024-3982 CVE-2024-4872 CVE-2024-7940 CVE-2024-7941 CVE-2025-6625 CVE-2026-13336 CVE-2026-13337 CVE-2026-13348 CVE-2026-13584 CVE-2026-15688 CVE-2026-31431 CVE-2026-77960 CVE-2026-86520 CVE-2026-86689 Bransys Mitsubishi Electric Hitachi Energy Schneider Electric FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · CISA Releases Eight Industrial Control Systems Advisories

1

SPOJENO PŘES CVE ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…

KEV ✓ EPSS 1.00 CVSS 7.8 CVE-2026-31431 ABB Linux výroba a průmysl energetika vodárenství US EU AT HU

tg: zneužíváno tg: zranitelnost tg: rozbor tp: průmyslové systémy

· CISA Advisories · ABB Ability Edgenius · Fortinet PSIRT · Linux Kernel Vulnerability copy.fail - CVE-2026-31431 · Elastic Security · Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild · CERT-EU · 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") · CERT.at · Copy Fail Update #1: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte · NKI Maďarsko · Riasztás a Linux rendszereket érintő Copy Fail sérülékenységről

1

1

Exploits and vulnerabilities in Q2 2026

The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these…

KEV ✓ · ransomware EPSS 1.00 CVE-2017-0199 CVE-2017-11882 CVE-2018-0802 CVE-2023-38831 CVE-2025-6218 CVE-2025-8088 CVE-2026-31431 CVE-2026-31635 CVE-2026-43284 CVE-2026-43494 CVE-2026-43500 CVE-2026-46300 CVE-2026-46331 Microsoft Kaspersky RU

· Securelist (Kaspersky) · Exploits and vulnerabilities in Q2 2026

1

Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

[PPSA-2026-003] The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.

KEV ✓ EPSS 1.00 CVE-2026-31431 CVE-2026-43284 CVE-2026-46300 Pilz výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

1

1

Lokale Privilegieneskalation im Linux-Kernel ("Dirty Frag" und "Copy Fail 2") - PoCs verfügbar, kein Patch

08. Mai 2026 Beschreibung Am 7. Mai 2026 wurden zwei neue Schwachstellen im Linux-Kernel öffentlich gemacht, die unter den Namen „Dirty Frag“ und „Copy Fail 2: Electric Boogaloo“ bekannt sind. Beide Schwachstellen ermöglichen lokalen, nicht privilegierten Benutzer:innen eine Eskalation auf root. Sie liegen in den In-Place-Entschlüsselungspfaden der Kernel-Module esp4, esp6 (IPsec/ESP) sowie rxrpc und nutzen Page-Cache-Writeprimitives aus, indem über splice(2), sendfile(2) bzw. MSG_SPLICE_PAGES…

KEV ✓ EPSS 1.00 CVE-2026-31431 CVE-2026-43284 AT

· CERT.at · Lokale Privilegieneskalation im Linux-Kernel ("Dirty Frag" und "Copy Fail 2") - PoCs verfügbar, kein Patch