CVE-2026-31431 Copy Fail Gives Local Attackers Root on Every Linux Distro Since 2017
A logic flaw in the Linux kernel algif_aead module gives any unprivileged local user root access on every major distro released since 2017. CISA added CVE-2026-31431 to the KEV catalog with a mandatory federal patch deadline. If you run Linux servers, patch today or assume compromise.