Security Compliance
Why SolarWinds Security Event Manager (SEM) is not affected by CVE-2026-31431 and CVE-2026-43284
This article explains why SolarWinds Security Event Manager (SEM) is not affected by CVE-2026-31431 (also known as the Linux Copy Fail vulnerability) and CVE-2026-43284 (also known as the Linux Dirty Frag vulnerability).
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-31431 and CVE-2026-43284, vulnerabilities affecting Linux-based systems.
Product section
Cause
CVE-2026-31431, also known as the “Copy Fail” vulnerability, is a local privilege escalation vulnerability that affects multiple Linux-based distributions. This vulnerability requires local access to the machine and low-level privileges to execute commands and leads to unauthorized privilege escalation to the root user.
CVE-2026-43284, also known as the “Dirty Frag” vulnerability, is another local privilege escalation vulnerability that also affects multiple Linux-based distributions. This vulnerability is similar in nature to the “Copy Fail” vulnerability where it requires local access to the machine and low-level privileges to execute commands and leads to unauthorized privilege escalation to the root user.
Resolution
While SolarWinds Security Event Manager (SEM) is shipped as a Linux-based image, the default user does not have access to a command line interface. Users also do not have access to the root user unless specifically requested and a disclaimer is acknowledged. It is therefore not affected by CVE-2026-31431 and CVE-2026-43284.