logo

9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access

ID: 447b3168-b38b-553b-a46f-342c658cc82e

STIX ID: report--447b3168-b38b-553b-a46f-342c658cc82e

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Deeba Ahmed

...
...

Theori disclosed a logic bug in the Linux kernel's algif_aead crypto module (CVE-2026-31431, “Copy Fail”) that, since a 2017 optimization, can let an unprivileged local user write four bytes into the page cache of privileged binaries (e.g., /usr/bin/su) and gain reliable root escalation using a small Python PoC. The flaw is cross-distribution (Ubuntu 24.04, Amazon Linux 2023, RHEL 10.1, SUSE 16), leaves minimal forensic traces because changes occur in memory, and is mitigated by a kernel patch (commit a664bf3d603d) or disabling the algif_aead module.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.