logo

Linux cryptographic code flaw offers fast route to root

ID: 5b6a81c9-411a-54ff-b721-e0e5a6bcb4be

STIX ID: report--5b6a81c9-411a-54ff-b721-e0e5a6bcb4be

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-05-06

...
...

A newly disclosed local privilege escalation vulnerability in the Linux kernel's authencesn cryptographic template (CVE-2026-31431, "Copy Fail") allows an unprivileged user to write four controlled bytes into the page cache of any readable file, enabling modification of setuid binaries to gain root; a small Python proof-of-concept exists and major Linux distributions have issued patches. The flaw is not remotely exploitable by itself but can be chained with RCE or compromised CI/SSH sessions and poses particular risk to multi-tenant systems, containers, and Kubernetes nodes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.