AWS: privilege escalation
UnratedCVE-2026-31431 · Published May 6, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-026-AWS Scope: Amazon Content Type: Important (requires attention) Publication Date: 05/06/2026 18:30 PM PDT Modification Date: 05/26/2026 14:45 PM PDT ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of an issue in the Linux kernel ( CVE-2026-31431 ) that could potentially allow an authenticated local user to escalate privileges. As a best practice, AWS recommends that you apply all security patches and software version updates as soon as they become available. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Related Security Bulletins - copy.fail variants Security Bulletin 2026-029-AWS - CVE-2026-46300 (also known as "Fragnesia") Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) References: CVE-2026-31431 To find more information about "Dirty Frag" and other issues in Amazon Linux kernels ( CVE-2026-31431 ), please refer to our Security Bulletin Please email aws-security@amazon.com...
Affected versions
Details and references
Bulletin ID: 2026-026-AWS Scope: Amazon Content Type: Important (requires attention) Publication Date: 05/06/2026 18:30 PM PDT Modification Date: 05/26/2026 14:45 PM PDT ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of an issue in the Linux kernel ( CVE-2026-31431 ) that could potentially allow an authenticated local user to escalate privileges. As a best practice, AWS recommends that you apply all security patches and software version updates as soon as they become available. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Related Security Bulletins - copy.fail variants Security Bulletin 2026-029-AWS - CVE-2026-46300 (also known as "Fragnesia") Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) References: CVE-2026-31431 To find more information about "Dirty Frag" and other issues in Amazon Linux kernels ( CVE-2026-31431 ), please refer to our Security Bulletin Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-026-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-31431 Bulletin ID: 2026-026-AWS Scope: Amazon Content Type: Important (requires attention) Publication Date: 05/06/2026 18:30 PM PDT Modification Date: 05/26/2026 14:45 PM PDT ⚠️This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of an issue in the Linux kernel ( CVE-2026-31431 ) that could potentially allow an authenticated local user to escalate privileges. As a best practice, AWS recommends that you apply all security patches and software version updates as soon as they become available. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Related Security Bulletins - copy.fail variants Security Bulletin 2026-029-AWS - CVE-2026-46300 (also known as "Fragnesia") Security Bulletin 2026-027-AWS - CVE-2026-43284 and CVE-2026-31431 (also known as "DirtyFrag" or copy.fail 2) References: CVE-2026-31431 To find more information about "Dirty Frag" and other issues in Amazon Linux kernels ( CVE-2026-31431 ), please refer to our Security Bulletin Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.", "items": [ { "name": "Learn", "linkU
- Severity from
- no source yet
- Also known as
- CVE-2026-46300, CVE-2026-43284
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 8 | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver | Unrated | No fix yet |
| May 7 | Dirty Frag and other issues in Amazon Linux kernels | Unrated | No fix yet |
| May 4 | Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent | Unrated | No fix yet |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | High7.2 | 1.103.0 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer... | Unrated | No fix yet |