Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <87bjf0hpzd.fsf@gentoo.org>
Date: Thu, 30 Apr 2026 08:22:30 +0100
From: Sam James <sam@...too.org>
To: oss-security@...ts.openwall.com
Cc: Jan Schaumann <jschauma@...meister.org>
Subject: Re: CVE-2026-31431: CopyFail: linux local privilege
 scalation

Greg KH <greg@...ah.com> writes:

> On Thu, Apr 30, 2026 at 09:01:22AM +0200, Salvatore Bonaccorso wrote:
>> Hi,
>> 
>> On Thu, Apr 30, 2026 at 05:52:37AM +0100, Sam James wrote:
>> > Eddie Chapman <eddie@...k.net> writes:
>> > 
>> > > On 29/04/2026 21:23, Jan Schaumann wrote:
>> > >> Affected and fixed versions
>> > >> ===========================
>> > >> Issue introduced in 4.14 with commit
>> > >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in
>> > >> 6.18.22 with commit
>> > >> fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
>> > >> Issue introduced in 4.14 with commit
>> > >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in
>> > >> 6.19.12 with commit
>> > >> ce42ee423e58dffa5ec03524054c9d8bfd4f6237
>> > >> Issue introduced in 4.14 with commit
>> > >> 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 and fixed in
>> > >> 7.0 with commit
>> > >> a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
>> > >> https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
>> > >> https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
>> > >> https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
>> > >
>> > > So this is one of the worst make-me-root vulnerabilities in the kernel
>> > > in recent times. I see that on the 11th of April 6.19.12 & 6.18.22
>> > > were released with the fix backported.
>> > >
>> > > Longterm 6.12, 6.6, 6.1, 5.15, 5.10 have not received the fix and I
>> > > don't see anything in the upstream stable queues yet as I write. My
>> > > guess is backporting that far back is not as straightforward. As this
>> > > was introduced in 2017 all those older kernels are affected, right? Or
>> > > am I missing something?
>> > 
>> > It does not apply cleanly, no. Attached is the workaround we're going to
>> > use. I'm not an expert on IPSec but I think this is the lesser evil.
>> > 
>> > I attempted a backport but ran into a few API changes and wasn't
>> > confident enough to muck around with it, especially for something to
>> > deploy immediately.
>> 
>> Backports have just been posted, for 6.12.y:
>> https://lore.kernel.org/stable/2026043038-unwilling-slogan-a20e@gregkh/T/#t
>> 
>> (but I do not see them yet for all versions, but guess following soon)
>
> Yes, they are following, I'll be doing some kernel releases in an hour
> or so with these all applied.

Thanks to both you and Eric, and thanks Salvatore for spotting.

>
> thanks,
>
> greg k-h

Download attachment "signature.asc" of type "application/pgp-signature" (419 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.