VYPR
advisoryPublished Sep 17, 2026· 1 source

Linux Kernel Vulnerability CVE-2026-31431 Allows Privilege Escalation in ABB Ability Edgenius

ABB Ability Edgenius versions prior to 3.2.4.1 are vulnerable to CVE-2026-31431, a Linux kernel flaw that allows local users or compromised containers to gain root privileges.

ABB has issued a security advisory for its ABB Ability Edgenius platform, detailing a critical vulnerability tracked as CVE-2026-31431, also known as "Copy Fail." This flaw resides within the Linux kernel's cryptographic subsystem and can be exploited by a locally authenticated user or a compromised container workload to escalate privileges to root.

The vulnerability stems from an incorrect resource transfer within the kernel's algif_aead cryptographic algorithm interface. This issue, introduced through an "in-place operation," can lead to unexpected behavior or data integrity problems during cryptographic processes. While successful exploitation requires local code execution, the risk is amplified in shared, containerized, or multi-tenant environments where an attacker could gain complete control over the affected system node.

ABB Ability Edgenius versions ranging from 3.2.0.0 up to, but not including, 3.2.4.1 are affected by this vulnerability. The CVSS v3.1 base score for CVE-2026-31431 is 7.8 (HIGH), with a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a significant risk of confidentiality, integrity, and availability compromise.

The platform, ABB Ability Edgenius, is an edge computing solution designed to connect to control systems, collect and contextualize operational data, and host applications for real-time insights and AI-driven recommendations. It is deployed globally across critical infrastructure sectors including Critical Manufacturing, Energy, and Water and Wastewater.

ABB has released an update, Edgenius version 3.2.4.1, which corrects the vulnerability. The company strongly recommends that customers apply this update at their earliest convenience. While no additional lower-privilege users are typically present on Edgenius installations by default, ABB also advises customers to limit access to SSH or Cockpit as a mitigating factor.

This vulnerability was publicly reported and disclosed prior to the advisory's issuance. ABB stated that at the time of the advisory, they had not received any reports of this vulnerability being actively exploited in the wild against their Edgenius product. However, the underlying Linux kernel flaw impacts kernels used by most major Linux distributions released since 2017.

Successful exploitation could allow an attacker with local access to execute arbitrary code, cause the system node to become unavailable, or gain administrative control. The vulnerability is not exploitable remotely, requiring an attacker to have physical access or valid SSH credentials to the affected system.

ABB encourages users to refer to their specific cybersecurity advisories (available in PDF and CSAF formats) for more detailed information and guidance. The company emphasizes that while they provide information on vulnerabilities, they assume no responsibility for errors and disclaim liability for damages arising from the use of the information or described hardware/software.

Synthesized by Vypr AI