Proof-of-concept exploit available for Linux 'Copy Fail' vulnerability (CVE-2026-31431)
ID: 3f6d79dd-c315-51d8-ac2c-afc4f186df12
STIX ID: report--3f6d79dd-c315-51d8-ac2c-afc4f186df12
Feed Name: Sophos Blogs
On April 29, 2026 the 'Copy Fail' vulnerability (CVE-2026-31431), a high-severity (CVSS 7.8) local privilege escalation affecting Linux kernels shipped since 2017, was publicly disclosed with proof-of-concept exploit code; it allows unprivileged users to gain root by corrupting the kernel in-memory page cache, is reported reliable across major distributions, and organizations are advised to apply vendor kernel updates or temporary mitigations, especially for multi-tenant and container hosts, while SophosLabs monitors for exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
