CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments
ID: 8f51bf03-41a4-55a5-80b9-074fc2e5a7dd
STIX ID: report--8f51bf03-41a4-55a5-80b9-074fc2e5a7dd
Feed Name: Microsoft Security
Date Published: 2026-05-02
Date Updated: 2026-05-02
Author: Microsoft Defender Security Research Team
**CVE-2026-31431 ("Copy Fail")** is a high-severity local privilege escalation in the Linux kernel crypto subsystem that allows an unprivileged user to perform a controlled in-memory corruption of readable files (including setuid binaries) via AF_ALG/splice interactions, enabling deterministic escalation to root and potential container escape; it affects kernels from 2017 onward across major distributions. Microsoft Defender provides technical analysis, an example attack chain, evidence of a public PoC and limited testing activity, detection mappings for Defender products, and immediate mitigation guidance (patching, disabling AF_ALG, isolation and node recycling).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
