logo

Linux Kernel 0-Day “Copy Fail” Affects Distros Since 2017

ID: ef5265b7-19aa-58a7-b2f4-d179a2e76431

STIX ID: report--ef5265b7-19aa-58a7-b2f4-d179a2e76431

Feed Name: Cyber Press

Threat Score
92/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

A critical Linux kernel zero-day dubbed 'Copy Fail' (CVE-2026-31431) allows unprivileged local users to gain deterministic root access and enables container escape by exploiting a logic bug in algif_aead/AF_ALG combined with splice(), causing a controlled 4-byte write into page cache pages of readable files; a 732-byte Python exploit was weaponized and the issue affects kernels since 4.14 across major distributions, with an upstream patch available and immediate mitigations provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.