<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <link rel="alternate" type="text/html" href="https://status.sr2.uk/"/>
    <title>Link Helpdesks on SR2® Cloud Status</title>
    <link>https://status.sr2.uk/affected/link-helpdesks/</link>
    <description>Incident history</description>
    <generator>github.com/cstate</generator>
    <language>en</language>
    
    <lastBuildDate>2026-05-22T08:00:00+00:00</lastBuildDate>
    <updated>2026-05-22T08:00:00+00:00</updated>
    
    
    
      <atom:link href="https://status.sr2.uk/affected/link-helpdesks/index.xml" rel="self" type="application/rss+xml" />
    
    
      <item>
        <title>[Resolved] Emergency patching for CVE-2026-48063 affecting WhatsApp channels</title>
        <link>https://status.sr2.uk/issues/2026-05-22-whatsapp-service-patch/</link>
        <pubDate>Fri, 22 May 2026 08:00:00 +0000</pubDate>
        <guid>https://status.sr2.uk/issues/2026-05-22-whatsapp-service-patch/</guid>
        <category>2026-05-22 11:30:00</category>
        <description>We have performed emergency patching to address a vulnerability, CVE-2026-48063, discovered in an open source component we use to provide WhatsApp functionality. As a result of this it may be necessary to relink your WhatsApp channel if you self-manage your handset. If we fully manage your instance, no action is required as we will test and relink the channel for you.
Due to the critical nature of this issue we have not been able to do this within a pre-scheduled maintenance window.</description>
        <content type="html">&lt;p&gt;We have performed emergency patching to address a vulnerability, CVE-2026-48063, discovered in an open source
component we use to provide WhatsApp functionality.
&lt;strong&gt;As a result of this it may be necessary to relink your WhatsApp channel if you self-manage your handset.&lt;/strong&gt;
If we fully manage your instance, no action is required as we will test and relink the channel for you.&lt;/p&gt;
&lt;p&gt;Due to the critical nature of this issue we have not been able to do this within a pre-scheduled maintenance window.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://cloud.sr2.uk/docs/link/e2e_channels&#34;&gt;Instructions for relinking the channel&lt;/a&gt; can be found in our online
documentation.&lt;/p&gt;
&lt;p&gt;As always, if you have any concerns please &lt;a href=&#34;https://www.sr2.uk/support&#34;&gt;contact our helpdesk&lt;/a&gt;.&lt;/p&gt;
</content>
      </item>
    
      <item>
        <title>WhatsApp Malicious Messages</title>
        <link>https://status.sr2.uk/issues/2026-05-01-whatsapp-ai-rich-response/</link>
        <pubDate>Fri, 01 May 2026 09:00:00 +0000</pubDate>
        <guid>https://status.sr2.uk/issues/2026-05-01-whatsapp-ai-rich-response/</guid>
        <category></category>
        <description>A WhatsApp security advisory announced a discovered vulnerability, tracked as CVE-2026-23866, arises from incomplete validation of AI rich response messages that contain Instagram Reels references within WhatsApp.
This vulnerability allows a malicious user to craft a message that triggers the victim’s device to fetch and process media content from an external URL. In some cases, the media content may invoke OS‑controlled custom URL scheme handlers, potentially executing arbitrary code or launching unintended applications.</description>
        <content type="html">&lt;p&gt;A &lt;a href=&#34;https://www.whatsapp.com/security/advisories/2026&#34;&gt;WhatsApp security advisory&lt;/a&gt; announced a discovered vulnerability,
tracked as &lt;a href=&#34;https://app.opencve.io/cve/CVE-2026-23866&#34;&gt;CVE-2026-23866&lt;/a&gt;, arises from incomplete validation of AI rich
response messages that contain Instagram Reels references within WhatsApp.&lt;/p&gt;
&lt;p&gt;This vulnerability allows a malicious user to craft a message that triggers the victim’s device to fetch and process
media content from an external URL.
In some cases, the media content may invoke OS‑controlled custom URL scheme handlers,
potentially executing arbitrary code or launching unintended applications.
The CVSS score of 4.3 indicates moderate impact and a non‑zero but limited likelihood of exploitation.&lt;/p&gt;
&lt;p&gt;We have confirmed via MDM that all Android handsets operated by SR2 Communications have since upgraded to unaffected
versions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you self-manage your handset for your Link helpdesk&amp;rsquo;s WhatsApp channel it is your responsibility to follow vendor
security advisories and ensure that the handset operating system and applications are secured and regularly patched.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;As always, if you have any concerns please &lt;a href=&#34;https://www.sr2.uk/support&#34;&gt;contact our helpdesk&lt;/a&gt;.&lt;/p&gt;
</content>
      </item>
    
      <item>
        <title>[Resolved] copy.fail (CVE-2026-31431)</title>
        <link>https://status.sr2.uk/issues/2026-04-29-copy-fail/</link>
        <pubDate>Wed, 29 Apr 2026 09:00:00 +0000</pubDate>
        <guid>https://status.sr2.uk/issues/2026-04-29-copy-fail/</guid>
        <category>2026-05-01 12:00:00</category>
        <description>We were made aware of CVE-2026-31431 on the afternoon of the 29th April via our threat intelligence feeds and later via a CERT-EU advisory. This affected our systems running Rocky Linux 9 as well as our legacy systems running Debian 13. Patches were not immediately available however migrations could be applied.
Rocky Linux 9 Most of our core systems, including those supporting internal infrastructure and single-sign on, are running Rocky Linux 9.</description>
        <content type="html">&lt;p&gt;We were made aware of &lt;a href=&#34;https://app.opencve.io/cve/CVE-2026-31431&#34;&gt;CVE-2026-31431&lt;/a&gt; on the afternoon of the 29th April
via our threat intelligence feeds and later via a
&lt;a href=&#34;https://cert.europa.eu/publications/security-advisories/2026-005/&#34;&gt;CERT-EU advisory&lt;/a&gt;.
This affected our systems running Rocky Linux 9 as well as our legacy systems running Debian 13.
Patches were not immediately available however migrations could be applied.&lt;/p&gt;
&lt;h2 id=&#34;rocky-linux-9&#34;&gt;Rocky Linux 9&lt;/h2&gt;
&lt;p&gt;Most of our core systems, including those supporting internal infrastructure and single-sign on, are running Rocky
Linux 9. This is based on Red Hat Enterprise Linux 9.
Unfortunately, the kernel does not have the &lt;code&gt;algif_aead&lt;/code&gt; subsystem compiled as a module and our only option was to
prevent the code from initialising via adding kernel arguments at boot time and subsequently rebooting.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;grubby --update-kernel&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;ALL --args&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;initcall_blacklist=algif_aead_init&amp;#34;&lt;/span&gt;
reboot
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Our Prometheus-based monitoring was able to verify all services returning after reboots.&lt;/p&gt;
&lt;h2 id=&#34;debian-13&#34;&gt;Debian 13&lt;/h2&gt;
&lt;p&gt;Some Link Secure Digital Helpdesks hosted on behalf of the Centre for Digital Resilience use our legacy deployment
model.
For these systems we were able to remove the offending module without requiring a reboot:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;echo &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;install algif_aead /bin/false&amp;#34;&lt;/span&gt; &amp;gt; /etc/modprobe.d/disable-algif-aead.conf
rmmod algif_aead 2&amp;gt;/dev/null
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;verification&#34;&gt;Verification&lt;/h2&gt;
&lt;p&gt;To ensure that the mitigation was applied across all hosts, we use Ansible:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4&#34;&gt;&lt;code class=&#34;language-yaml&#34; data-lang=&#34;yaml&#34;&gt;    - &lt;span style=&#34;color:#f92672&#34;&gt;name&lt;/span&gt;: &lt;span style=&#34;color:#ae81ff&#34;&gt;Verify CVE-2026-31431 mitigation&lt;/span&gt;
      &lt;span style=&#34;color:#f92672&#34;&gt;ansible.builtin.command&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;lsmod | grep -E &amp;#39;^{{ item }}\\s&amp;#39;&amp;#34;&lt;/span&gt;
      &lt;span style=&#34;color:#f92672&#34;&gt;loop&lt;/span&gt;:
        - &lt;span style=&#34;color:#ae81ff&#34;&gt;algif_aead&lt;/span&gt; &lt;span style=&#34;color:#75715e&#34;&gt;# copy fail&lt;/span&gt;
      &lt;span style=&#34;color:#f92672&#34;&gt;register&lt;/span&gt;: &lt;span style=&#34;color:#ae81ff&#34;&gt;module_check&lt;/span&gt;
      &lt;span style=&#34;color:#f92672&#34;&gt;failed_when&lt;/span&gt;: &lt;span style=&#34;color:#ae81ff&#34;&gt;module_check.rc != 1&lt;/span&gt;
      &lt;span style=&#34;color:#f92672&#34;&gt;changed_when&lt;/span&gt;: &lt;span style=&#34;color:#66d9ef&#34;&gt;false&lt;/span&gt;
      &lt;span style=&#34;color:#f92672&#34;&gt;check_mode&lt;/span&gt;: &lt;span style=&#34;color:#66d9ef&#34;&gt;false&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We do not run any systems where unrelated users have shell access to the host, meaning that this could only have been
used as part of a chain of vulnerabilities first involving obtaining remote code execution as a user. For this reason
we do not believe any exploitation was possible in our systems.&lt;/p&gt;
&lt;p&gt;Further, an
&lt;a href=&#34;https://garrido.io/notes/podman-rootless-containers-copy-fail/&#34;&gt;analysis of the protections offered by Podman&lt;/a&gt;
published shortly after by Gabriel Garrido details how our new deployment architecture would further have limited
the &amp;ldquo;blast radius&amp;rdquo; of this kind of vulnerability should an exploitation have been possible.&lt;/p&gt;
&lt;p&gt;In light of this, we will be prioritising a move of the remaining Link helpdesks using the legacy model to our new
Rocky Linux 9 model.&lt;/p&gt;
&lt;p&gt;As always, if you have any concerns please &lt;a href=&#34;https://www.sr2.uk/support&#34;&gt;contact our helpdesk&lt;/a&gt;.&lt;/p&gt;
</content>
      </item>
    
      <item>
        <title>WhatsApp Message Send Issue</title>
        <link>https://status.sr2.uk/issues/2026-03-25-whatsapp-issue-banned-accounts/</link>
        <pubDate>Wed, 25 Mar 2026 03:00:00 +0000</pubDate>
        <guid>https://status.sr2.uk/issues/2026-03-25-whatsapp-issue-banned-accounts/</guid>
        <category>2026-03-31 16:15:00</category>
        <description>Resolved: This issue appears to only affect cases where no conversation history exists with the contact the message is sent to. Due to the nature of the helpdesk, messages are only sent to users that have already sent a message to the helpdesk, so we do not believe this issue will affect our users. We encourage you to get in touch if you do see any issues with your WhatsApp channel however we are no longer monitoring this situation closely.</description>
        <content type="html">&lt;p&gt;&lt;strong&gt;Resolved&lt;/strong&gt;: This issue appears to only affect cases where no conversation history exists with the contact the message
is sent to.
Due to the nature of the helpdesk, messages are only sent to users that have already sent a message to the helpdesk, so
we do not believe this issue will affect our users.
We encourage you to get in touch if you do see any issues with your WhatsApp channel however we are no longer monitoring
this situation closely.

  &lt;span class=&#34;faded&#34;&gt;(16:15 UTC — Mar 31)&lt;/span&gt;

&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Monitoring&lt;/strong&gt;: We are not aware of this issue affecting any helpdesk currently however we continue to monitor.
A fix has been found by the upstream project and will be rolled out once released formally.

  &lt;span class=&#34;faded&#34;&gt;(15:00 UTC — Mar 27)&lt;/span&gt;

&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Monitoring&lt;/strong&gt;: We have been made aware of an issue with the WhatsApp integration that we use where for some accounts,
mostly accounts that have been banned and subsequently unbanned, users are noticing errors on message send.
A fix is being investigated by the integration developer.
Technical details can be followed on GitHub at &lt;a href=&#34;https://github.com/WhiskeySockets/Baileys/issues/2441&#34;&gt;https://github.com/WhiskeySockets/Baileys/issues/2441&lt;/a&gt;.

  &lt;span class=&#34;faded&#34;&gt;(03:00 UTC — Mar 25)&lt;/span&gt;

&lt;/p&gt;
</content>
      </item>
    
      <item>
        <title>WhatsApp introducing usernames</title>
        <link>https://status.sr2.uk/issues/2025-12-01-whatsapp-usernames/</link>
        <pubDate>Mon, 01 Dec 2025 12:00:00 +0000</pubDate>
        <guid>https://status.sr2.uk/issues/2025-12-01-whatsapp-usernames/</guid>
        <category>2026-03-17 20:00:00</category>
        <description>Update - We have deployed updates to the WhatsApp channel and currently do not expect that there will be issues sending and receiving messages.
&amp;ndash; 2026-03-17
Investigating - We&amp;rsquo;re aware that WhatsApp have begun rolling out a new feature replacing phone numbers with usernames. We are monitoring this rollout and making updates to our integration as it evolves, but we expect there to be minor disruptions to service until the roll out is complete.</description>
        <content type="html">&lt;p&gt;&lt;em&gt;Update&lt;/em&gt; - We have deployed updates to the WhatsApp channel and currently do not expect that there will be issues
sending and receiving messages.&lt;/p&gt;
&lt;p&gt;&amp;ndash; 2026-03-17&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Investigating&lt;/em&gt; - We&amp;rsquo;re aware that WhatsApp have begun rolling out a new feature replacing phone numbers with usernames.
We are monitoring this rollout and making updates to our integration as it evolves, but we expect there to be minor
disruptions to service until the roll out is complete.&lt;/p&gt;
&lt;p&gt;&amp;ndash; 2025-12-01&lt;/p&gt;
</content>
      </item>
    
  </channel>
</rss>
