logo

Copy Fail: New Linux bug enables Root via page‑cache corruption

ID: 0b401aa7-d44c-5c29-9d2d-7dcb5c39db2a

STIX ID: report--0b401aa7-d44c-5c29-9d2d-7dcb5c39db2a

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Pierluigi Paganini

...
...

CVE-2026-31431 ('Copy Fail') is a logic bug in the Linux kernel's authencesn crypto template that lets an unprivileged local user inject four controlled bytes into the page cache of any readable file via AF_ALG and splice(), enabling stealthy, in-memory modification of setuid binaries (e.g., /usr/bin/su) and local privilege escalation to root; a 732-byte PoC reliably demonstrated full root compromise on Ubuntu, RHEL, SUSE and Amazon Linux (kernels 6.12–6.18), and the researchers published a PoC for defenders and vendors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.