Copy Fail: New Linux bug enables Root via page‑cache corruption
ID: 0b401aa7-d44c-5c29-9d2d-7dcb5c39db2a
STIX ID: report--0b401aa7-d44c-5c29-9d2d-7dcb5c39db2a
Feed Name: Security Affairs
CVE-2026-31431 ('Copy Fail') is a logic bug in the Linux kernel's authencesn crypto template that lets an unprivileged local user inject four controlled bytes into the page cache of any readable file via AF_ALG and splice(), enabling stealthy, in-memory modification of setuid binaries (e.g., /usr/bin/su) and local privilege escalation to root; a 732-byte PoC reliably demonstrated full root compromise on Ubuntu, RHEL, SUSE and Amazon Linux (kernels 6.12–6.18), and the researchers published a PoC for defenders and vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
