logo

Attackers are cashing in on fresh 'CopyFail' Linux flaw

ID: 748588d4-7b25-5137-ac51-2ec19e8d07b5

STIX ID: report--748588d4-7b25-5137-ac51-2ec19e8d07b5

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Carly Page

...
...

CVE-2026-31431 (“CopyFail”) is a Linux kernel flaw that allows low-privilege users to modify data they should only be able to read, enabling reliable local privilege escalation to root across mainstream kernels since 2017; a public Python PoC works unmodified across multiple major distributions, prompting immediate patches, CISA KEV listing with an emergency patch deadline, and Microsoft warnings of observed exploitation/testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.