logo

Active In-The-Wild Exploit: “Copy Fail” Grants Root Privileges on Millions of Linux Systems

ID: f9e52432-cdaf-5c67-a1f1-b67359526edc

STIX ID: report--f9e52432-cdaf-5c67-a1f1-b67359526edc

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

CVE-2026-31431 ('Copy Fail') is a logic bug in the Linux kernel crypto path (AF_ALG + splice) introduced in 2017 that allows deterministic 4-byte writes into the page cache, enabling local unprivileged users to modify setuid binaries and gain root privileges; Theori published a 100% reliable PoC and CISA added the CVE to its Known Exploited Vulnerabilities catalog, patches were released April 1, 2026, and an interim mitigation (blacklisting algif_aead) is provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.