logo

Proof-of-concept exploit available for Linux 'Copy Fail' vulnerability (CVE-2026-31431)

ID: 3f6d79dd-c315-51d8-ac2c-afc4f186df12

STIX ID: report--3f6d79dd-c315-51d8-ac2c-afc4f186df12

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-05-01

Date Updated: 2026-05-03

...
...

On April 29, 2026 the 'Copy Fail' vulnerability (CVE-2026-31431), a high-severity (CVSS 7.8) local privilege escalation affecting Linux kernels shipped since 2017, was publicly disclosed with proof-of-concept exploit code; it allows unprivileged users to gain root by corrupting the kernel in-memory page cache, is reported reliable across major distributions, and organizations are advised to apply vendor kernel updates or temporary mitigations, especially for multi-tenant and container hosts, while SophosLabs monitors for exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.