CVSS: v3.1: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
The HPE Juniper Networking PSIRT is aware of the Linux kernel vulnerability related to the algif_aead crypto module, known as "Copy Fail", being tracked as CVE-2026-31431.Copy Fail is a logic bug in the crypto module's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system.Below is the current status of Juniper Networking products potentially impacted by the Copy Fail vulnerability:
Other products not listed above are still under investigation.
Unless otherwise noted, this issue affects all software versions of the products listed above.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was discovered by a third-party upstream provider.
Software releases will be updated to resolve this issue and made available on the Customer Support Downloads site.
Note: Juniper SIRT's policy is not to evaluate releases that are beyond End of Engineering (EOE) or End of Life (EOL).
For most products, successful exploitation requires direct access to the system shell or console. Security best practices for limiting shell access (EVO) or console access (SSR, Mist) to the system will mitigate the risk of malicious exploitation.
2026-05-07: Initial Publication2026-05-11: Added response for Mist Edge2026-06-01: Added statement for Apstra