www.microsoft.com 5/2/2026, 4:11:06 AM · via preferred

Microsoft warns CVE-2026-31431 lets Linux users get root in cloud

Moxa Linux Flaw Lets Local Users Gain Root Access via Dirty Frag

Moxa has issued a critical security advisory (MPSA-263140) concerning vulnerabilities in its Linux-based operating systems that allow local attackers to gain root privileges. The weaknesses are identified as 'Copy Fail' (CVE-2026-31431) and 'Dirty Frag' (CVE-2026-43284, CVE-2026-43500). The advisory underscores the risks in non-containerized…

First seen 2026-05-01T21:21:17.916Z · Last seen 2026-05-27T10:32:00.184Z

CyberSIXT Evidence Panel
Primary Source access.redhat.com
CISA KEV Listed in KEV
Patch Patch Available

MICROSOFT Defender researchers warn of CVE-2026-31431, a Copy Fail vulnerability that enables Linux root privilege escalation across cloud environments, affecting multiple major Linux distributions including Red Hat, SUSE, Ubuntu and AWS Linux. The flaw, a local privilege escalation in the Linux kernel’s AF_ALG crypto subsystem, could allow an unprivileged user to gain UID 0 by abusing a 4‑byte overwrite in the kernel page cache, potentially enabling container breakout and cross‑container impacts.

Exploitation has been demonstrated in proof‑of‑concept form, and the vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog, heightening urgency for patching. Mitigation guidance published by Microsoft includes applying patches when available or using interim measures such as disabling the affected feature, enforcing network isolation, and tightening access controls, alongside prompt log review for signs of exploitation.

The research also provides detection and hunting guidance within Microsoft Defender XDR, emphasising that the vulnerability is highly impactful in cloud, CI/CD and Kubernetes environments where untrusted code execution is common.

View Primary Source Via www.microsoft.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline