Description <…"/> Description
<…"/> Description
<…"/>
VDB

GCP-2026-028

GCP-2026-028 PUBLISHED

<p><strong>Published: </strong>2026-05-05</p><p><strong>Updated:</strong> 2026-05-27</p><h3 class="hide-from-toc" data-text="Description" id="description_28" tabindex="-1">Description</h3><table> <thead> <tr> <th width="70%">Description</th> <th>Severity</th> <th>Notes</th> </tr> </thead> <tbody> <tr> <td> <p><a href="https://knowledge.broadcom.com/external/article?articleNumber=439189">CVE-2026-31431</a>, also known as "Copy Fail," is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel that allows an unprivileged user to gain root access. Disclosed in late April 2026, it stems from a logic flaw in the kernel's cryptographic subsystem (algif_aead) introduced in 2017.</p> <h4 data-text="What should I do?" id="what-should-i-do_10" tabindex="-1">What should I do?</h4> <p>Google recommends that customers protect their Linux Guest VMs by updating the kernel on all Linux VMs. Major distributions have released or are rolling out fixes.</p> </td> <td>High</td> <td> <a href="https://knowledge.broadcom.com/external/article?articleNumber=439189">CVE-2026-31431</a> </td> </tr> </tbody> </table>

Timeline

  • Apr 30, 2026 PoC Published
  • May 5, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›