Page MenuHomeVyOS Platform

Kernel: T8610: Update Linux Kernel to 6.6.137 (fix CVE-2026-31431) aka copy.fail
Closed, ResolvedPublicBUG

Description

Several Linux distributions are since about year 2017 affected by Local Linux kernel privilege escalation vulnerability (CVE-2026-31431) named https://copy.fail/

Classified as CVSS score 7.8 (high).

It seems like at least VyOS 1.4.4 is affected (and 1.5, rolling and stream until new releases are out).

Description:

Copy Fail: 732 Bytes to Root on Every Major Linux Distributions

Xint Code disclosed CVE-2026-31431, an authencesn scratch-write bug chaining AF_ALG + splice() into a 4-byte page cache write. A 732-byte PoC gets root on Ubuntu, Amazon Linux, RHEL, SUSE.

Possible mitigations:

Add any of these as kernel boot flag (grub):

Blacklist affected functions:

initcall_blacklist=algif_aead_init

Blacklist just the af_alg interface itself:

initcall_blacklist=af_alg_init

Blacklist just the affected algorithm:

initcall_blacklist=crypto_authenc_esn_module_init

References:

https://www.cvedetails.com/cve/CVE-2026-31431/

https://security-tracker.debian.org/tracker/CVE-2026-31431

https://access.redhat.com/security/cve/cve-2026-31431

https://xint.io/blog/copy-fail-linux-distributions

Details

Version
All?
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability
Forum thread
https://forum.vyos.io/t/copy-fail-cve-2026-31431-affecting-vyos/17418

Event Timeline

Probably related:

[docker-29.x backport] seccomp: Block AF_ALG sockets in default profile (CVE-2026-31431)
#52501

https://github.com/moby/moby/pull/52501

Apachez set Forum thread to https://forum.vyos.io/t/copy-fail-cve-2026-31431-affecting-vyos/17418.May 1 2026, 7:10 PM

Versions up to v1.3.8 are not affected. However, from v1.4.x onwards, including v1.5.0 and Rolling releases, all versions are affected.

c-po renamed this task from Local Linux kernel privilege escalation vulnerability (CVE-2026-31431) aka copy.fail to Kernel: T8610: Update Linux Kernel to 6.6.137 (fix CVE-2026-31431) aka copy.fail.May 2 2026, 7:38 PM
c-po changed the task status from Open to In progress.
c-po assigned this task to josephillips85.
c-po triaged this task as High priority.
c-po updated the task description. (Show Details)

Good to know 1.3.8 is not affected, so having been denied access to later versions saved me from this vulnerability - thanks @syncer !
BTW, please also check out Dirty Frag while you're at it, no CVE yet. Mitigation (disallow loading of modules: esp4, esp6, rxrpc) breaks ipsec.

Hi. Kind of a newbie here tracking Kernel updates with VyOS, and I'm not sure if it's appropriate to ask here? I'm running Stream 2026.03, and would like to stay on the Stream builds, so will the 6.6.137 Kernel be added to the next Stream build, or is there a way I can pull it into my current router? The nightly rolling are running are running a 6.18 Kernel, and again I really would like to stay on a Stream build to get the fix for the copy.fail vulnerability. thanks!

@taylorcb updating the Kernel manually is not supported by us. The next stream build will have an updated Kernel with these vulnerabilities mitigated.

ok thanks for the info. Stream 2026.02 and 2026.03 were released very close to each other, so do you have a guesstimate on when a new version of Stream will be released? I might jump to a nightly build from early May until the next Stream is out to pick up the fix for this issue. thanks for everything!

Is there any update on this at all, please? Stream is still sitting vulnerable as far as I can see. Even a Stream 2006.03-1 with just an updated kernel would have been vastly preferable, versus no mitigation and no new Stream image for >3 months since the CVE disclosures (and five months since the last Stream release).

Like most users, I've ended up on Rolling/Nightly; but it'd be good to know whether a fixed Stream image is coming soon for those of us who run and evangelise VyOS, but can't afford LTS for home use (and don't want the churn of nightly). Thanks in advance!

This comment was removed by syncer.

Hello @syncer since you removed my comment (not sure why, it was not offensive), could you please write a better one (when the next Stream will be released) while you are at it? Thanks!

Hello @syncer since you removed my comment (not sure why, it was not offensive), could you please write a better one (when the next Stream will be released) while you are at it? Thanks!

FWIW I saw your comment, I just had no way to reply without also getting deleted. Since your post was deleted but mine was ignored, I got the message.

The project looks good, but I've been around this block over the last 25 or so years. You inspired me, so I ditched VyOS and just configured Alpine myself. Now I'm pushing multigig WAN -> LAN, routing my /29 and /48, shaping with CAKE on ingress and egress, running nftables with GeoIP filtering, and most importantly — my current LTS kernel isn't vulnerable to a pile of CVEs. Oh, and only 300 MB RAM. Win. Thanks for the prompt! :)

Hi guys,

Thanks for your input on T8610! Just a quick note: this task has been closed.
Questions about new streams or other platforms aren't really related to this task, so it'd be great if those could go to the forum instead.

Thanks for understanding!

Hi guys,

Thanks for your input on T8610! Just a quick note: this task has been closed.
Questions about new streams or other platforms aren't really related to this task, so it'd be great if those could go to the forum instead.

Thanks for understanding!

Apologies. Forum posts just result in 'We don't know' or 'Some time'. Six months was too long for us, sorry. All the best.

Hi guys,

Thanks for your input on T8610! Just a quick note: this task has been closed.
Questions about new streams or other platforms aren't really related to this task, so it'd be great if those could go to the forum instead.

Thanks for understanding!

Apologies from me as well, I couldn't post to the forum because I was banned there about 2 years ago.