VU#260001: Linux kernel contains local privilege escalation vulnerability (Copy Fail)

2026-05-08T20:52:14Zd37a30b5d4e4d56703c39fd2f1bb49c4605953eed8d5665db67bc4f677c762f9
AF_ALGDICOMGGUFOllamaOrthancRadwareSGLangTerrariumXSSalgif_aeadconfiguration-managementcopy.failin-memory-modificationinformation-disclosurejinja2-sstilinux-kernellocal-privilege-escalationpage-cachequantizationremote-code-executionsandbox-escapesetuidsupply-chainunauthenticated

What happened

This collection summarizes multiple high-impact vulnerabilities disclosed in 2026 across OS, application, and service layers. Notable issues include: a Linux kernel local privilege escalation ("Copy Fail") in algif_aead/AF_ALG allowing reliable 4‑byte in‑memory writes to any readable file/page cache enabling setuid binary tampering and root escalation (CVE-2026-31431); an unauthenticated configuration modification endpoint in DRC INSIGHT Central Office Services that allows remote configuration/credential changes and exfiltration (CVE-2026-5756); an unauthenticated remote heap memory disclosure

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
d37a30b5d4e4d56703c39fd2f1bb49c4605953eed8d5665db67bc4f677c762f9
Enrichment time
2026-05-08T20:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.