logo

New Linux ‘Copy Fail’ flaw gives hackers root on major distros

ID: 80ba2454-4f74-5ae9-a879-314eb766cc20

STIX ID: report--80ba2454-4f74-5ae9-a879-314eb766cc20

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Bill Toulas

...
...

A local privilege escalation vulnerability called “Copy Fail” (CVE-2026-31431) affecting Linux kernels since 2017 allows an unprivileged user to get root by performing a controlled 4-byte write to the page cache via AF_ALG sockets and splice(); a 732-byte PoC exploit reportedly reliably roots major distributions, patches were released upstream (early April) and mitigations (disabling algif_aead/AF_ALG) are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.