VDB
CVE-2026-31431
CVE-2026-31431
PUBLISHED
KEV
CVSS 7.800000190734863 HIGH
CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. The issue originates in the Linux kernel’s cryptographic subsystem and impacts kernels used by most major Linux distributions released since 2017. Successful exploitation requires local code execution, however, in shared, containerized, or multi‑tenant environments this may increase the security risk
EPSS 3.44% · 88.5th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.44%
88.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | ABB Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100 | |
| ABB | B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602 | |
| ABB | ABB Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Server - vE1000 | |
| ABB | B&R Industrial Automation GmbH Linux for B&R <=12 | |
| ABB | ABB Ability Edgenius >=3.2.0.0|<3.2.4.1 installed on ABB Ability Edgenius Gateway - E3100C | |
| ABB | B&R Industrial Automation GmbH X20EDS410 /all |
Timeline
- Mar 8, 2026 VulnCheck XDB Entry
- Apr 20, 2026 CVE Published
- Apr 23, 2026 Security Advisory
- Apr 29, 2026 VulnCheck XDB Entry
- Apr 29, 2026 VulnCheck XDB Entry
- Apr 29, 2026 VulnCheck XDB Entry
- Apr 30, 2026 VulnCheck XDB Entry
- Apr 30, 2026 VulnCheck XDB Entry
- Apr 30, 2026 VulnCheck XDB Entry
- Apr 30, 2026 VulnCheck XDB Entry
- Apr 30, 2026 VulnCheck XDB Entry
- Apr 30, 2026 VulnCheck XDB Entry
References
- https://psirt.abb.com/csaf/2026/7paa024620.json advisory
- https://search.abb.com/library/Download.aspx?DocumentID=7PAA024620&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-31431 advisory
- https://psirt.abb.com/csaf/2026/sa26p010.json advisory
- https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf advisory
- https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf advisory
- Blog third-party-analysis
- Why your code is safe from Copy Fail on Fastly Compute third-party-analysis