Tec Nikan
فارسی
Talk to us
All news

A Linux Kernel Bug Gives Root on ABB's Edgenius Gateway

ICSA-26-260-06 covers a kernel crypto flaw that lets a local user or a compromised container escalate to root on the Gateway bE100. The same CVE already appears in IoT malware.

edge gatewaycontainer securityABBLinux kernelprivilege escalation

CISA published ICSA-26-260-06 on 17 September for ABB Ability Edgenius running on the Gateway bE100. The flaw is CVE-2026-31431, nicknamed Copy Fail, scored 7.8 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The root cause is incorrect memory handling in the Linux kernel's algif_aead cryptographic interface.

Affected versions run from 3.2.0.0 up to but not including 3.2.4.1. ABB fixed it in 3.2.4.1 and recommends immediate deployment, with interim mitigation limited to restricting SSH and Cockpit access. ABB notes that no additional unprivileged users exist by default on Edgenius installations.

It is not remotely exploitable — an attacker needs local access, physical or through SSH credentials. What makes it worth reading is the phrasing of the impact: exploitation allows a locally authenticated user or compromised container workload to gain elevated root privileges. Risk is highest in shared, containerised or multi-tenant deployments.

Edge gateways are sold on exactly that capability — run your own containers next to the process data pipeline, keep the analytics local, keep the PLC untouched. A container-escape path through the host kernel undoes the boundary that makes the proposition safe, and it does so without any flaw in the container runtime or in the workload itself.

There is a second reason not to sit on this one. The same CVE appears as one of four privilege escalation paths in KATARU, an IoT malware family analysed by Nozomi Networks Labs on 9 September. The exploit is not theoretical and it is not waiting on someone to write it.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.