Skip to content

removed CVE-2026-31431 from the resolved list#1017

Merged
Chr1st0ph3rTurn3r merged 1 commit into
masterfrom
add-i95-65077-cve-mitigation
May 15, 2026
Merged

removed CVE-2026-31431 from the resolved list#1017
Chr1st0ph3rTurn3r merged 1 commit into
masterfrom
add-i95-65077-cve-mitigation

Conversation

@Chr1st0ph3rTurn3r
Copy link
Copy Markdown
Contributor

removed CVE-2026-31431 from the resolved list and added it under I95-65077 in the caveats. This issue was not resolved, but mitigated in 6.2.11.

…65077 in the caveats. This issue was not resolved, but mitigated in 6.2.11.

### Caveats

- **I95-65077 Mitigation for CVE-2026-31431:** CVE-2026-31431 has been mitigated in this release and will be fully resolved in an upcoming release.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this information here because CVE-2026-31431 (CopyFail) will still show up in a vulnerability scan?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes. Because the CVE is linked to the kernel version, scanners are not going to know that we mitigated the vulnerability in the boot parameters. Attempting to head off any customer confusion.

Copy link
Copy Markdown

@iwbarker iwbarker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would keep CVE-2026-31431 in the main list, and add the caveat to explain the mitigation. Text of the caveat is fine by me.

@Chr1st0ph3rTurn3r Chr1st0ph3rTurn3r merged commit c67fa8d into master May 15, 2026
1 check passed
@Chr1st0ph3rTurn3r Chr1st0ph3rTurn3r deleted the add-i95-65077-cve-mitigation branch May 15, 2026 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants