Linux Kernel 0-Day “Copy Fail” Grants Root Access Across Major Distros Since 2017
ID: 3e3a810d-c433-5460-85af-ed266d52c55c
STIX ID: report--3e3a810d-c433-5460-85af-ed266d52c55c
Feed Name: GBHackers
Threat Score
Security researchers disclosed CVE-2026-31431 "Copy Fail", a deterministic Linux kernel local privilege escalation in the cryptographic subsystem that lets unprivileged users perform a controlled four-byte overwrite to in-memory page cache—potentially achieving immediate root and enabling container escapes; the flaw affects kernels since 4.14 across major distributions and has been patched in recent releases, with a temporary mitigation available by blocking algif_aead.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
