logo

CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments

ID: 8f51bf03-41a4-55a5-80b9-074fc2e5a7dd

STIX ID: report--8f51bf03-41a4-55a5-80b9-074fc2e5a7dd

Feed Name: Microsoft Security

Threat Score
80/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Microsoft Defender Security Research Team

...
...

**CVE-2026-31431 ("Copy Fail")** is a high-severity local privilege escalation in the Linux kernel crypto subsystem that allows an unprivileged user to perform a controlled in-memory corruption of readable files (including setuid binaries) via AF_ALG/splice interactions, enabling deterministic escalation to root and potential container escape; it affects kernels from 2017 onward across major distributions. Microsoft Defender provides technical analysis, an example attack chain, evidence of a public PoC and limited testing activity, detection mappings for Defender products, and immediate mitigation guidance (patching, disabling AF_ALG, isolation and node recycling).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.