logo

Linux cryptographic code flaw offers fast route to root

ID: ae141f8f-45e1-56c6-8ad7-9f0f0ca5e9a3

STIX ID: report--ae141f8f-45e1-56c6-8ad7-9f0f0ca5e9a3

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Thomas Claburn

...
...

A newly disclosed Linux kernel local privilege escalation called `Copy Fail` (CVE-2026-31431) allows an unprivileged user to overwrite four bytes in the page cache of any readable file, enabling modification of `setuid` binaries to achieve root. A 10-line Python proof-of-concept makes exploitation straightforward when local or chained access (e.g., via RCE, malicious CI jobs, or compromised SSH sessions) is available; the flaw is particularly concerning for multi-tenant hosts, shared-kernel containers and Kubernetes nodes. Major distributions including Debian, Ubuntu, SUSE and Red Hat have issued patches; severity is reported as 7.8/10.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.