A local privilege escalation vulnerability (CVE-2026-31431, "Copy Fail") exists in the Linux kernel's algif_aead module due to improper handling of in-place cryptographic operations, which could also be used to escape a container. The update also addresses multiple other unspecified security issues in the Cryptographic API and Packet sockets subsystems. The article advises applying the USN-8441-1 update but does not provide specific affected or fixed kernel version numbers or a workaround.
It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Packet sockets; (CVE-2026-31504, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028)