Linux Kernel 0-Day “Copy Fail” Affects Distros Since 2017
ID: ef5265b7-19aa-58a7-b2f4-d179a2e76431
STIX ID: report--ef5265b7-19aa-58a7-b2f4-d179a2e76431
Feed Name: Cyber Press
Threat Score
A critical Linux kernel zero-day dubbed 'Copy Fail' (CVE-2026-31431) allows unprivileged local users to gain deterministic root access and enables container escape by exploiting a logic bug in algif_aead/AF_ALG combined with splice(), causing a controlled 4-byte write into page cache pages of readable files; a 732-byte Python exploit was weaponized and the issue affects kernels since 4.14 across major distributions, with an upstream patch available and immediate mitigations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
