logo

CISA says ‘Copy Fail’ flaw now exploited to root Linux systems

ID: eac85d08-3efb-5a75-a551-fd46e7ffd4ba

STIX ID: report--eac85d08-3efb-5a75-a551-fd46e7ffd4ba

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Sergiu Gatlan

...
...

CVE-2026-31431 (“Copy Fail”) is a Linux kernel privilege-escalation vulnerability in the algif_aead cryptographic interface that Theori disclosed with a reportedly reliable PoC capable of rooting multiple mainstream distributions; CISA confirmed in-the-wild exploitation, added the flaw to its KEV catalog, and ordered federal agencies to patch within two weeks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.