Executive brief
ABB Ability Edgenius is an edge computing platform used in critical infrastructure (manufacturing, energy, water, chemical) to collect operational data and host real-time analytics. A Linux kernel flaw in the cryptographic subsystem allows authenticated local users or compromised container workloads to escalate privileges to root, gaining complete system control and enabling arbitrary code execution or denial of service on affected nodes.
Technical details
CVE-2026-31431 is a privilege escalation vulnerability in the Linux kernel's algif_aead cryptographic algorithm interface, where an incorrect in-place operation was introduced with mismatched source and destination data mappings. The flaw exists in the kernel's cryptographic subsystem and affects most major Linux distributions released since 2017. An attacker with local code execution (either a local user or a compromised container workload) can invoke the vulnerable cryptographic interface to trigger incorrect memory handling, allowing escalation from normal user privileges to root (administrative) access. No remote exploitation is possible; local access (physical or via SSH credentials) is required. The vulnerability has been publicly disclosed. ABB released a fix in Edgenius version 3.2.4.1, which incorporates the Linux kernel security update. Mitigation includes limiting SSH and Cockpit access and noting that no additional lower-privilege users exist by default on Edgenius installations.
Affected products
- ABB Ability Edgenius >=3.2.0.0 to <3.2.4.1
Timeline
- 2026-09-17: disclosed: CVE-2026-31431 publicly disclosed
- 2026-09-17: patched: Fix available in Edgenius 3.2.4.1
- 2026-09-17: advisory: CISA ICS Advisory ICSA-26-260-06 published