logo

How Cloudflare responded to the “Copy Fail” Linux vulnerability

ID: 69eb0586-ee6d-5063-bd6b-e8d76271c412

STIX ID: report--69eb0586-ee6d-5063-bd6b-e8d76271c412

Feed Name: Cloudflare Blog

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Chris J Arges

...
...

Cloudflare describes the discovery and response to the 'Copy Fail' Linux kernel local privilege escalation (CVE-2026-31431), an out-of-bounds write in the algif_aead/AF_ALG crypto path that allows unprivileged attackers to taint page cache and gain root by modifying setuid binaries; Cloudflare validated that behavioral detections flagged the exploit, performed fleet-wide hunting with no evidence of compromise, and deployed eBPF-based mitigations (bpf-lsm), visibility, and patched kernels with no customer impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.