CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure — Threadlinqs Intelligence
As of 2026-08-03, CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure is a high-severity vulnerability threat attributed to UMBRAL BISON (Belarus), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1831 · Severity: HIGH · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: UMBRAL BISON · Belarus · ESPIONAGE
CVE-2026-31431 ("Copy Fail"), a CVSS 7.8 Linux kernel local privilege escalation flaw in the algif_aead AEAD crypto template, was publicly disclosed with a working PoC on 2026-04-29 and exploited in
CVE-2026-31431, nicknamed "Copy Fail" by researchers at Theori, is a logic flaw in the Linux kernel's cryptographic subsystem that was introduced by an in-place memory optimization merged in 2017 and only fully reverted in April 2026 (upstream commit a664bf3d603d, "crypto: algif_aead - Revert to operating out-of-place"). The kernel's algif_aead implementation reuses source memory as destination memory during AEAD cryptographic operations even though the source and destination come from different mappings. By chaining the AF_ALG socket interface with the splice() system call, an unprivileged local user can perform a controlled 4-byte write into the kernel page cache of any readable file — including setuid binaries such as /usr/bin/su — without ever writing to disk. Corrupting privilege-checking instructions inside a setuid binary's in-memory page allows the attacker to bypass access controls and spawn a root shell.
Unlike earlier Linux LPE bugs such as Dirty Cow and Dirty Pipe, Copy Fail does not require winning a race condition, making it deterministic and reliable across a very wide range of kernel builds. Virtually every mainstream Linux distribution shipping a kernel built between 2017 and the April 2026 patch is affected (Ubuntu, Debian, RHEL, SUSE/openSUSE, Fedora, Arch, Rocky Linux, AlmaLinux, Oracle Linux, Amazon Linux 2023, NixOS, Arista EOS), with NVD configuration data also flagging exposure in Siemens SIMATIC S7-1500 embedded Linux firmware. Because containers on a shared host frequently share a base-image kernel, the bug also enables container breakout and lateral movement across multi-tenant cloud and Kubernetes environments — CrowdStrike and Wiz both flagged the blast radius as touching a significant share of cloud Linux workloads and Kubernetes clusters.
Red Hat privately received the report on 2026-03-23; the upstream fix landed 2026-04-01; public disclosure with a working PoC and technical writeup followed on 2026-04-29, with a Metasploit module merged the same window (rapid7/metasploit-framework PR #21395) supporting AMD64 and AArch64 targets. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-05-01 with a federal remediation deadline of 2026-05-15. CrowdStrike OverWatch detected Belarus-nexus exploitation activity attributed to UMBRAL BISON "in just over 20 hours" after disclosure — the fastest adversary-attribution window discussed in the report — with roughly 94% of that first-day activity assessed as PoC-based testing rather than operational post-exploitation.
UMBRAL BISON (tracked elsewhere as UNC1151, FrostyNeighbor, UAC-0057, White Lynx, Storm-0257, TA445, and PUSHCHA, and publicly known as the Ghostwriter operation) is assessed by CrowdStrike as likely a Belarus-based, state-nexus adversary active since at least 2017 (previously the RepeatingUmbra cluster) that conducts intelligence-collection and enables information operations in support of Belarusian government interests, with a documented focus on Ukraine, Poland, and Lithuania. In related, previously reported Ghostwriter/UNC1151 activity (geofenced PDF-phishing campaigns against Ukrainian government/military and Polish industrial, healthcare, pharmaceutical, and logistics targets), the group used decoy documents impersonating Ukrtelecom, RAR archives containing JavaScript downloaders, and a PicassoLoader-to-Cobalt-Strike-Beacon delivery chain with server-side victim fingerprinting and manual operator validation before payload deployment. No malware, C2 infrastructure, or post-exploitation tooling specific to the UMBRAL BISON Copy Fail testing activity itself has been publicly disclosed by CrowdStrike; the actor's tradecraft documented here for the exploitation event is limited to rapid weaponization of the public PoC/Metasploit tooling.
Mitigation is available via kernel patch (all major vendors shipped fixed builds by early May 2026) or, where patching is not immediately possible, by blacklisting the algif_aead module (
Weaknesses (CWE)
CWE-669, CWE-1288
Target sectors: government administration, military, defense, industrial, health, pharmaceuticals, logistics, cloud-hosting, technology
Target regions: ukraine, poland, lithuania, 151 - Eastern Europe, Global
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-31431, T1595.002, T1588.001, T1588.005, T1588.006, T1566.001, T1566.002, T1059.006, T1068, T1548.001, T1211