Active In-The-Wild Exploit: “Copy Fail” Grants Root Privileges on Millions of Linux Systems
ID: f9e52432-cdaf-5c67-a1f1-b67359526edc
STIX ID: report--f9e52432-cdaf-5c67-a1f1-b67359526edc
Feed Name: securityonline.info
Threat Score
CVE-2026-31431 ('Copy Fail') is a logic bug in the Linux kernel crypto path (AF_ALG + splice) introduced in 2017 that allows deterministic 4-byte writes into the page cache, enabling local unprivileged users to modify setuid binaries and gain root privileges; Theori published a 100% reliable PoC and CISA added the CVE to its Known Exploited Vulnerabilities catalog, patches were released April 1, 2026, and an interim mitigation (blacklisting algif_aead) is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
