[Updated on May 11, 2026] This document outlines the impact of the CVE-2026-31431 (Copy Fail) security vulnerability on Alibaba Cloud ECS official Linux images, the image remediation plan, and how to fix existing instances.
Impact scope, community status, and ECS remediation
|
Distribution |
Affected versions |
Permanent fix |
Mitigation |
ECS image status |
|
Alibaba Cloud Linux |
2–4 |
Upgrade the kernel package and reboot to apply the fix. See CVE-2026-31431 Kernel Upgrade Fix. |
A mitigation is available: Disable the AF_ALG protocol family. Mitigation for Alibaba Cloud Linux by Disabling the AF_ALG Protocol Family |
Updated images:
Release plan:
|
|
Anolis OS |
7–8 |
|
No mitigation announced by the community. |
In planning. |
|
Debian |
10–13 |
|
No mitigation announced by the community. |
Updated images:
Release notes:
Release plan:
|
|
Ubuntu |
18–24 |
The community has not yet released a permanent fix. |
Community mitigation available:
|
Updated images:
Release notes:
Release plan:
|
|
Red Hat Enterprise Linux |
8–10 |
|
No plans at this time. |
|
|
CentOS |
8 |
EOL. No permanent fix is available. |
No mitigation announced by the community. |
No plans. |
|
CentOS Stream |
8–10 |
The community has not yet released a permanent fix. A patch has been merged into the repository but has not been released as a package. |
No mitigation announced by the community. |
No plans at this time. Images will be updated once the community provides a fix. |
|
Rocky Linux |
8–10 |
|
No mitigation announced by the community. |
Updated images:
Release notes:
Release plan:
|
|
AlmaLinux |
8–10 |
|
No mitigation announced by the community. |
Updated images:
Release notes:
Release plan:
|
|
Fedora |
33–42 |
|
No mitigation announced by the community. |
No plans. ECS does not currently offer any images for Fedora 42. Future Fedora 42 images will include the fix. |
|
SUSE Linux Enterprise Server |
12–16 |
|
In planning. |
|
|
openSUSE |
15–16 |
|
In planning. |
Remediation for existing instances
For most distributions, applying the permanent fix involves upgrading kernel-related packages and rebooting the system.