Operators reported a suspected root compromise on a Debian web host running kernel 6.12.90+deb13.1-amd64, with the Linux kernel af_alg module identified as the only notable artifact left after the intrusion. Posts to the oss-sec mailing list said no specific CVE, exploit chain, or threat actor had been confirmed, but the incident raised concern that af_alg may be serving as an in-the-wild exploitation vector against distribution kernels.
As an immediate containment step, administrators said they blacklisted af_alg across their systems, and one referenced recommendation also called for blacklisting algif_aead. The discussion noted that af_alg is already considered deprecated for 7.2, underscoring growing concern around the module while the reported compromise remains under investigation and unverified against a publicly identified vulnerability such as CVE-2026-31431.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Following the suspected compromise, the affected operators said they had blacklisted the af_alg kernel module across their systems as an immediate mitigation. A related reply also noted a suggestion to blacklist algif_aead.
An oss-sec post reported that a web host running Debian kernel 6.12.90+deb13.1-amd64 was allegedly compromised through a root exploit. The only notable trace observed after the incident was loading of the af_alg kernel module, but no specific CVE, exploit chain, or threat actor was confirmed.
In the oss-security thread, Simon McVittie said the compromised Debian host might have been exploited via CVE-2026-46331 ('packet_edit_meme'), another local root vulnerability. He noted it had been fixed in Debian 6.12.94 and disclosed in a Debian advisory on 2026-06-21, suggesting attackers could have known about it.
In an oss-security reply, Solar Designer said the compromised Debian host was running an outdated 6.12.90 kernel and noted that Debian 6.12.95 included fixes for publicly exploited vulnerabilities CVE-2026-46242 and CVE-2026-53362. The message cautioned that af_alg loading alone did not confirm a new af_alg exploit and suggested the attacker may have used previously fixed issues instead.
A reference titled "Copy Fail - CVE-2026-31431" was published, indicating public disclosure or reporting on the vulnerability. The provided content does not include additional event details beyond the topic and publication record.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcenki.gov.hu
Open sourcecopy.fail
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.