Date: 2026-04-30 Updated: 2026-05-04
Updated: 2026-05-06
NOTE:
All running resources MUST be either patched or have mitigation
in place or affected services disabled by 2026-05-13, 00:00 UTC.
Sites failing to act or respond to requests from the EGI CSIRT team risk site suspension.
CRITICAL risk vulnerability concerning the Linux kernel with very
easy public exploit leading to local privilege escalation to root.
It is extensively described at [R 1].
EGI SVG ID : EGI-SVG-2026-12
CVE ID : CVE-2026-31431
CVSSv3.x Score:
Urgent action is required on hosts giving access to unprivileged users,
e.g. grid worker nodes, but also container hosts, notebook servers and
CI runners.
At this time, patched kernels look available for all relevant distributions.
Please check the references listed at the bottom of this advisory for your
distribution(s).
There are several mitigation options, some of which are documented here
and/or in references listed below. In particular, this strategy has been
found to work on RHEL and derivatives:
A second mitigation option is to install a BPF filter, as exemplified in
this repository provided by the CERN Computer Security Team:
https://gitlab.cern.ch/ComputerSecurity/mitigations/cve-2026-31431
Compared to the CVSS risk assessment detailed in [R 4], in our deployment scenarios, the “Scope” parameter needs to have “Changed” as value, which causes the EGI SVG score to have a significantly higher, more appropriate value.
TLP:CLEAR information - Unlimited distribution
https://advisories.egi.eu/Advisory-EGI-SVG-2026-12
https://advisories.egi.eu/Advisory-SVG-CVE-2026-31431
Minor updates may be made without re-distribution to the sites.
This advisory is subject to the Creative Commons licence
https://creativecommons.org/licenses/by/4.0/ and
the EGI (https://www.egi.eu/) Software Vulnerability Group
must be credited. -----------------------------
Comments or questions should be sent to
svg-rat at mailman.egi.eu
Vulnerabilities relevant for EGI can be reported at
report-vulnerability at egi.eu
(see [R 99] for further details, and other information on SVG)
[R 9] https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigation
[R 98] https://confluence.egi.eu/display/EGIBG/CSIRT+monitoring+for+exposure+to+%27CRITICAL%27+vulnerabilities
[R 99] https://confluence.egi.eu/display/EGIBG/SVG+Advisories
SVG was alerted to this vulnerability by Barbara Krasovec