Story perspectives
CISA Flags Critical Linux Root Flaw, Mandates May Patch
5/4/2026
1 of 1
Story summary
- CISA added Linux flaw CVE-2026-31431 to its KEV catalog after confirming active exploitation.
- The CVSS-7.8 bug, affecting Linux distributions since 2018 and stemming from bugs introduced in 2011, 2015 and 2017, lets an unprivileged user obtain root via a 732-byte Python payload that exploits it with system calls.
- Patches for kernel versions 6.18.22, 6.19.12 and 7.0 are available, requiring agencies to patch by May 15 2026 or disable the feature per CISA.
