Linux cryptographic code flaw offers fast route to root
ID: ae141f8f-45e1-56c6-8ad7-9f0f0ca5e9a3
STIX ID: report--ae141f8f-45e1-56c6-8ad7-9f0f0ca5e9a3
Feed Name: The Register (Security)
A newly disclosed Linux kernel local privilege escalation called `Copy Fail` (CVE-2026-31431) allows an unprivileged user to overwrite four bytes in the page cache of any readable file, enabling modification of `setuid` binaries to achieve root. A 10-line Python proof-of-concept makes exploitation straightforward when local or chained access (e.g., via RCE, malicious CI jobs, or compromised SSH sessions) is available; the flaw is particularly concerning for multi-tenant hosts, shared-kernel containers and Kubernetes nodes. Major distributions including Debian, Ubuntu, SUSE and Red Hat have issued patches; severity is reported as 7.8/10.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
