CopyFail Kernel Vulnerability (CVE-2026-31431)

SweetAction

3CX MVP
Gold Partner
Advanced Certified
Joined
Jan 19, 2018
Messages
3,461
Reaction score
2,316
Opening this thread because I know it's coming.

https://copy.fail/ was released into the wild. I'm sure people will ask when it will be patched, so this thread is for 3CX to state when the upstream patches will be pushed into 3CX updates.
 
1777887208684.png
 
@Benedikt Machens we are aware of this as this was released on Friday.
Its under testing phase now. When we will ensure all is ok, we will push this to the 3CX Repo.
Ensure that you have Automatic Updates enabled on the PBX side
so when its released, the PBX will download this on the background.
 
  • Like
Reactions: NikosT_3CX
Hello,
I've tried to check if the update was available on the 3cx systems we manage, but it just give me the chance to install Alpha New 20.0 Update 9

Is it already available? Do I need to do something specific to force that update? I have checked 3 different systems.

Regards,
Alberto.
 
When is your automatic updates scheduled on these PBXs ?
 
Last edited:
On 2 of them I've scheduled it for today, right now
 
Just to clear things up, you won’t see this on the PBX side, you have to ssh to the machines and check the packet that has been updated after the Automatic Updates schedule triggers.
 
As long as we’re discussing kernel updates via automatic updates, there is also Dirty Frag now…
 
  • Like
Reactions: SweetAction
Oh, I know. :) I'm just mentioning it.
 
  • Like
Reactions: NikosT_3CX
Just to clear things up, you won’t see this on the PBX side, you have to ssh to the machines and check the packet that has been updated after the Automatic Updates schedule triggers.
Can you please share more about this? What do we need to check to see if they have been updated since I'm assuming the build number in the web dashboard will not change?
 
Just to clear things up, you won’t see this on the PBX side, you have to ssh to the machines and check the packet that has been updated after the Automatic Updates schedule triggers.

Nikos - can we get these OS side updates triggered by running an Update Now via API? We have an internal tool we use to execute updates for emergencies like this. I would rather not have to wait for the scheduled automatic update to happen.
 
@pmterp you can check this via root ssh to the machine and check with " apt-cache policy linux-image-* " .
Depanding the installation you have the packet will appear on the appropriate section.
@aholmes-think the same applies for you. If you can do this on the OS via API then proceed like this.
 
  • Like
Reactions: pmterp
@aholmes-think the same applies for you. If you can do this on the OS via API then proceed like this.
Thanks for the assist. We'll get it done like that. For future, it would be lovely to be able to execute this through the standard API you have in the web console.
 
Can release dates be added to entries on the hotfix changelog? It would also be nice if security hotfix version was visibly exposed somewhere on the Management Console.
 
Will this patch also work for remote debian SBC's?
 

Members Online Now

No members online now.

Forum statistics

Threads
111,832
Messages
589,285
Members
164,662
Latest member
DejanMDS