Skip to content

Add SPO Seccomp mitigation for CVE-2026-31431#71

Merged
SergeyKanzhelev merged 2 commits intoGoogleCloudPlatform:masterfrom
timberlakeis:add-spo-seccomp-mitigation
Apr 30, 2026
Merged

Add SPO Seccomp mitigation for CVE-2026-31431#71
SergeyKanzhelev merged 2 commits intoGoogleCloudPlatform:masterfrom
timberlakeis:add-spo-seccomp-mitigation

Conversation

@timberlakeis
Copy link
Copy Markdown
Collaborator

Title: Add SPO Seccomp mitigation for CVE-2026-31431 (Copy Fail)

Description:
This adds a spo-seccomp-mitigation folder containing instructions and Kubernetes manifests to mitigate CVE-2026-31431 using the Security Profiles Operator (SPO). This profile is a copy of containerd’s default allowed syscalls but explicitly blocks AF_ALG (and AF_VSOCK), which the exploit requires.

@vinayakankugoyal
Copy link
Copy Markdown
Collaborator

LGTM FWIW

@SergeyKanzhelev SergeyKanzhelev merged commit 299e654 into GoogleCloudPlatform:master Apr 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants