New Linux ‘Copy Fail’ flaw gives hackers root on major distros
ID: 80ba2454-4f74-5ae9-a879-314eb766cc20
STIX ID: report--80ba2454-4f74-5ae9-a879-314eb766cc20
Feed Name: Bleeping Computer
Threat Score
A local privilege escalation vulnerability called “Copy Fail” (CVE-2026-31431) affecting Linux kernels since 2017 allows an unprivileged user to get root by performing a controlled 4-byte write to the page cache via AF_ALG sockets and splice(); a 732-byte PoC exploit reportedly reliably roots major distributions, patches were released upstream (early April) and mitigations (disabling algif_aead/AF_ALG) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
