ABB Ability Edgenius
CISA's ABB advisory covers CVE-2026-31431, a public Linux kernel flaw letting local users or compromised containers gain root on Ability Edgenius gateways.
ABB confirmed that CVE-2026-31431 (Copy Fail), a Linux kernel flaw in the algif_aead cryptographic interface (CWE-669), affects Ability Edgenius versions 3.2.0.0 to below 3.2.4.1 on bE100 gateways. A locally authenticated user or compromised container workload can gain root privileges, enabling arbitrary code execution or denial of service on the node. CVSS v3.1 score is 7.8, and the flaw impacts kernels shipped in most major Linux distributions since 2017. A fix is available and ABB reported no exploitation of Edgenius when the advisory was issued.