What is CVE-2026-31543?
In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt key bytes in read_key_from_user_keying When debug logging is enabled, read_key_from_user_keying() logs the first 8 bytes of the key payload and partially exposes the dm-crypt key. Stop logging any key bytes.
Timeline
- 2026-04-24Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Linux Kernel
Remediation Steps
- Enumerate Milesight camera models and current firmware versions
- Download vendor security updates from Milesight support website
- Test patches in non-production environment before deployment
- Disable remote access features if not required for operations
- Implement strict firewall rules limiting camera communication to internal networks
References
- https://git.kernel.org/stable/c/36f46b0e36892eba08978eef7502ff3c94ddba77
- https://git.kernel.org/stable/c/4897bd307ba8757c31a3325ba6730961be606016
- https://git.kernel.org/stable/c/ed8d91f469845d62d44c565a55d2ab1767969357
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json
- https://www.milesight.com/support
- https://nvd.nist.gov/vuln/detail/CVE-2026-31543
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of April 2026 (April 27 – May 3)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.