Ongoing updates on Copy.fail and variants
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the copy.fail or DirtyFrag class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available. Please see below for current patching timelines for affected services related to the Copy.fail kernel issue and all its variants. AWS recommends that customers apply all updates addressing these issues as soon as they are available. See more details at Security Bulletin (ID: 2026-030-AWS).
CSIRTS triage
- What
- A set of privilege escalation issues affecting the Linux Kernel.
- Who is affected
- AWS customers using the affected Linux kernel.
- Urgency
- Remediation is urgent due to the potential for exploitation.
- Action
- Apply all updates addressing these issues as soon as they are available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Linux kernel
Get an email when a new Linux kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-030-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-463007.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2026-43284EPSS puts this in the most-targeted tier (93.2% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.8% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-31431Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2026-43500EPSS puts this in the most-targeted tier (92.9% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-46300 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-43284 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-31431 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-43500 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
- unknownexploitedCVE-2026-31431aws
- unknownFragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernelaws
- unknownexploitedDirty Frag and other issues in Amazon Linux kernelsaws
- unknownexploitedMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 14, 2026)cert-fr-avis
- unknownUSN-8530-2: Linux kernel (HWE) vulnerabilitiesubuntu
- criticalHitachi Energy APM Edge Productcisa
- high[UPDATE] [high] Linux Kernel (Fragnesia): Vulnerability Allows Gaining Administrator Rightscert-bund
- highexploited[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rightscert-bund
- highexploitedCVE-2026-31431: crypto: algif_aead - Revert to operating out-of-placemsrc
- unknownMultiple vulnerabilities in Red Hat Linux kernel (July 31, 2026)cert-fr-avis
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownCVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation2026-08-20