[Updated on May 11, 2026] This document outlines the impact of the CVE-2026-31431 (Copy Fail) security vulnerability on Alibaba Cloud ECS official Linux images, the image remediation plan, and how to fix existing instances.
Impact scope, community status, and ECS remediation
Distribution | Affected versions | Permanent fix | Mitigation | ECS image status |
Alibaba Cloud Linux | 2–4 | Upgrade the kernel package and reboot to apply the fix. See CVE-2026-31431 Kernel Upgrade Fix. | A mitigation is available: Disable the AF_ALG protocol family. Mitigation for Alibaba Cloud Linux by Disabling the AF_ALG Protocol Family | Updated images:
Release plan:
|
Anolis OS | 7–8 |
| No mitigation announced by the community. | In planning. |
Debian | 10–13 |
| No mitigation announced by the community. | Updated images:
Release notes:
Release plan:
|
Ubuntu | 18–24 | The community has not yet released a permanent fix. | Community mitigation available:
| Updated images:
Release notes:
Release plan:
|
Red Hat Enterprise Linux | 8–10 |
| No plans at this time. | |
CentOS | 8 | EOL. No permanent fix is available. | No mitigation announced by the community. | No plans. |
CentOS Stream | 8–10 | The community has not yet released a permanent fix. A patch has been merged into the repository but has not been released as a package. | No mitigation announced by the community. | No plans at this time. Images will be updated once the community provides a fix. |
Rocky Linux | 8–10 |
| No mitigation announced by the community. | Updated images:
Release notes:
Release plan:
|
AlmaLinux | 8–10 |
| No mitigation announced by the community. | Updated images:
Release notes:
Release plan:
|
Fedora | 33–42 |
| No mitigation announced by the community. | No plans. ECS does not currently offer any images for Fedora 42. Future Fedora 42 images will include the fix. |
SUSE Linux Enterprise Server | 12–16 |
| In planning. | |
openSUSE | 15–16 |
| In planning. |
Remediation for existing instances
For most distributions, applying the permanent fix involves upgrading kernel-related packages and rebooting the system.