With CVE-2026-31431 a local privilege escalation vulnerability was discovered in the Linux Kernel. This affects all Mindbreeze InSpire appliances that have version 26.2 or older installed.
With the Mindbreeze InSpire 26.3 Release the vulnerability will be fixed by providing a non-vulnerable kernel.
For older Mindbreeze InSpire installations, the vulnerable call can be disabled with the steps presented in the following chapters.
The following steps should be performed on all member nodes of a Mindbreeze InSpire cluster:
If correctly deployed, the following command should output:
initcall_blacklist=algif_aead_init