logo

Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years

ID: dbfabf50-e4aa-51a3-8ad3-c2d788be30c4

STIX ID: report--dbfabf50-e4aa-51a3-8ad3-c2d788be30c4

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Justin Moore

...
...

Palo Alto Networks Unit 42 describes CVE-2026-31431 ("Copy Fail"), a deterministic local privilege escalation in the Linux kernel's AF_ALG/algif_aead crypto code affecting kernels 4.14–6.19.12; a 732-byte Python PoC can reliably overwrite four bytes in the page cache to tamper with setuid binaries (e.g., su, sudo), enabling root escalation across many major distributions. The advisory details root cause, exploitation steps, detection queries, recommended immediate patching or disabling of the algif_aead module as an interim mitigation, and notes public PoC availability and observed preliminary testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.