VU#260001: Linux kernel contains local privilege escalation vulnerability (Copy Fail)
2026-05-08T20:52:14Z•d37a30b5d4e4d56703c39fd2f1bb49c4605953eed8d5665db67bc4f677c762f9
AF_ALGDICOMGGUFOllamaOrthancRadwareSGLangTerrariumXSSalgif_aeadconfiguration-managementcopy.failin-memory-modificationinformation-disclosurejinja2-sstilinux-kernellocal-privilege-escalationpage-cachequantizationremote-code-executionsandbox-escapesetuidsupply-chainunauthenticated
What happened
This collection summarizes multiple high-impact vulnerabilities disclosed in 2026 across OS, application, and service layers. Notable issues include: a Linux kernel local privilege escalation ("Copy Fail") in algif_aead/AF_ALG allowing reliable 4‑byte in‑memory writes to any readable file/page cache enabling setuid binary tampering and root escalation (CVE-2026-31431); an unauthenticated configuration modification endpoint in DRC INSIGHT Central Office Services that allows remote configuration/credential changes and exfiltration (CVE-2026-5756); an unauthenticated remote heap memory disclosure
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- d37a30b5d4e4d56703c39fd2f1bb49c4605953eed8d5665db67bc4f677c762f9
- Enrichment time
- 2026-05-08T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.