HIGH: 'Copy Fail' Linux Kernel Bug Lets Locals Get Root, CISA Confirms Active Exploitation (CVE-2026-31431)
CVE-2026-31431, a logic flaw in the Linux kernel algif_aead module, lets unprivileged local users gain root on essentially every distribution released since 2017. CISA added it to the KEV catalog on May 1 with a federal mitigation deadline of May 15 after confirming active exploitation. A reliable public PoC is already circulating.