logo

Copy.Fail Linux Vulnerability

ID: 1fc5ac1b-ef57-5f5d-b604-5f791facf61d

STIX ID: report--1fc5ac1b-ef57-5f5d-b604-5f791facf61d

Feed Name: Schneier on Security

Threat Score
80/100

Date Published: 2026-05-12

Date Updated: 2026-05-13

Author: Bruce Schneier

...
...

copy.fail is a high-impact Linux kernel local privilege escalation disclosed with a working PoC that uses AF_ALG sockets and splice() to write four bytes at a time into the page cache of files the attacker does not own, bypassing on-disk integrity checks; it affects major distributions, can break shared-infrastructure isolation (containers, CI, WSL2), and requires kernel updates or custom seccomp profiles to mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.