Moxa issued advisory MPSA-263140 for multiple industrial and embedded computing product lines affected by three Linux kernel vulnerabilities: CVE-2026-31431 ("Copy Fail") and CVE-2026-43284 plus CVE-2026-43500 ("Dirty Frag"). The company said the flaws could allow unprivileged local users to gain administrative or root access on affected devices, with added risk of container escape and host compromise in environments running untrusted workloads. Canada’s Cyber Centre separately alerted operators to review Moxa’s guidance for impacted UC, V, VM, ioThinx, AIG, BXP, DRP, and RKP series products.
Because permanent fixes were not yet broadly available for all affected Moxa platforms, the vendor urged immediate mitigations such as blacklisting or unloading vulnerable kernel modules including rxrpc, esp4, and esp6, while warning that disabling esp4 and esp6 can break IPsec/VPN connectivity and some devices require bootloader changes because algif_aead is built into the kernel. For CTOS-based Debian systems, Moxa advised updating from Debian security repositories, reinstalling the x86 SDK, and rebooting. The advisory follows wider industry response to the same kernel bugs: CVE-2026-31431 was added to CISA’s Known Exploited Vulnerabilities catalog, Ubuntu released mitigations that disable the vulnerable module, and Red Hat published OpenShift guidance for Dirty Frag-related exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-26, Moxa published security advisory MPSA-263140 covering CVE-2026-31431, CVE-2026-43284, and CVE-2026-43500 across multiple industrial computing product lines. Moxa instructed customers to apply interim mitigations such as blacklisting or unloading vulnerable kernel modules and to monitor for permanent patch availability.
On 2026-05-18, Red Hat published remediation and mitigation guidance for OpenShift versions affected by CVE-2026-43284, including fixed z-stream releases and RHSA errata. Red Hat also stated CVE-2026-43500 does not affect OpenShift 4 or RHEL 9 and recommended blacklisting esp4, esp6, and rxrpc as an interim mitigation.
On 2026-05-13, AWS published security bulletin 2026-027 covering 'Dirty Frag' and related issues in Amazon Linux kernels. The reference indicates Amazon Linux issued vendor guidance for these kernel vulnerabilities.
On 2026-05-01, CISA added CVE-2026-31431 to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The entry set a remediation due date of 2026-05-15.
On 2026-04-29, the NVD entry for CVE-2026-31431 documented the Linux kernel algif_aead vulnerability, noting public exploit references and available stable kernel patches through kernel.org. The record described the flaw as a local privilege escalation issue affecting multiple kernel version ranges.
On 2026-04-29, Ubuntu disclosed the high-severity Linux kernel local privilege escalation flaw CVE-2026-31431 ('Copy Fail'). Ubuntu released updated kmod packages to disable the vulnerable algif_aead module as an interim mitigation while kernel image fixes were still pending.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecyber.gc.ca
Open sourceaccess.redhat.com
Open sourceaws.amazon.com
Open sourceweb.nvd.nist.gov
Open sourceubuntu.com
Open sourcemoxa.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.