Повышение привилегий в Linux
Содержание
Уязвимое программное обеспечение
- Linux: от 6.7 до 6.12.85
- Red Hat Enterprise Linux: 10
- Ubuntu: 24.04 LTS
- Suse Linux Enterprise Desktop: 15 SP7
- Astra Linux Common Edition: 1.6 «Смоленск»
- Debian GNU/Linux: 13
- SUSE Linux Enterprise High Performance Computing: 15 SP7
- РЕД ОС: 8.0
- SUSE Linux Enterprise High Availability Extension: 15 SP7
- ОСОН ОСнова Оnyx: 2.15
- Astra Linux Special Edition: 4.8
- SUSE Linux Enterprise Micro: 5.5
- Альт 8 СП: -
- Циркон 37К: z37k-2057
- АЛЬТ СП 10: -
- Platform V SberLinux OS Server: до 9.2.3-fstec
- Горизонт-ВС: 40-17-37-17
Последствия эксплуатации
PE: Повышение привилегий
Common Vulnerability Scoring System
Рейтинг: ВЫСОКИЙ
Оценка: 7.8
Вектор: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Вектор атаки: Локальный
Сложность атаки: Низкая
Требуемые привилегии: Низкие
Границы эксплуатации: Неизменный
Влияние на Конфиденциальность: Высокая
Влияние на Целостность: Высокая
Влияние на Доступность: Высокая
Метод эксплуатации
Манипулирование ресурсами.
Взаимодействие с пользователем: Отсутствует
Уменьшение последствий
Данная уязвимость устраняется официальным патчем вендора.
Наличие обновления: Есть
Common Weakness Enumeration
CWE: CWE-669
Описание: Некорректная передача ресурса между окружениями
Ссылки
- http://www.openwall.com/lists/oss-security/2026/04/29/26
- https://access.redhat.com/security/cve/cve-2026-31431
- https://altsp.su/obnovleniya-bezopasnosti/
- https://git.kernel.org/linus/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- https://github.com/insomnisec/Detections-CVE-2026-31431
- https://github.com/rootsecdev/cve_2026_31431
- https://github.com/theori-io/copy-fail-CVE-2026-31431
- https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/
- https://nvd.nist.gov/vuln/detail/CVE-2026-31431
- https://redos.red-soft.ru/support/secure/uyazvimosti-red-os-8-0/uyazvimost-kernel-lt-cve-2026-31431/
- https://security-tracker.debian.org/tracker/CVE-2026-31431
- https://ubuntu.com/security/CVE-2026-31431
- https://vuldb.com/vuln/358784
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2026-0512SE18MD
- https://wiki.astralinux.ru/x/3U8TH
- https://wiki.astralinux.ru/x/61ETH
- https://wiki.astralinux.ru/x/J1ITH
- https://wiki.astralinux.ru/x/KVITH
- https://wiki.astralinux.ru/x/PVITH
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv
- https://www.suse.com/security/cve/CVE-2026-31431.html
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/Оперативные_исправления/2026-04-30
- https://xint.io/blog/copy-fail-linux-distributions#the-fix-6
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2026-0518SE47
- https://altsp.su/obnovleniya-bezopasnosti/
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2026-0522SE17HF
- https://bdu.fstec.ru/vul/2026-06123
- https://bdu.fstec.ru/vul/2026-06123