BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux “Copy Fail” Bug Lets Local Users Gain Root

  • A critical Linux flaw allows an unprivileged local user to write to a file’s cache and escalate to root privileges.
  • The vulnerability, tracked as CVE-2026-31431, affects nearly all Linux distributions released since 2017.
  • Exploitation is reliable, works across containers, and can be triggered with a small 732-byte Python script.

Cybersecurity researchers from Xint.io and Theori disclosed a high-severity Linux kernel vulnerability on April 30, 2026, which a simple Python exploit can weaponize for full system control. Dubbed Copy Fail, this local privilege escalation flaw is tracked as CVE-2026-31431 with a CVSS score of 7.8.
The issue stems from a logic flaw introduced in a 2017 commit to the kernel’s algif_aead cryptographic module. Consequently, an unprivileged user can write four controlled bytes into the page cache of any readable file. This primitive enables the corruption of a setuid binary like “/usr/bin/su” to gain root access.
Successful exploitation uses a small Python script to trigger the write and execute shellcode. Meanwhile, the vulnerability’s impact is broad, affecting Amazon Linux, RHEL, SUSE, and Ubuntu distributions. The page cache is shared, so the flaw also has cross-container implications.
Researchers compare Copy Fail to the earlier Dirty Pipe vulnerability, noting a similar page cache manipulation goal. However, Copy Fail presents a unique and dangerous combination of traits. According to David Brumley of Bugcrowd, the flaw allows a writable page cache page in an AEAD operation’s scatterlist.
“This vulnerability is unique because it has four properties that almost never appear together: it’s portable, tiny, stealthy, and cross-container,” a Xint.io spokesperson stated. The flaw is reliably triggered without race conditions, making it a significant threat. Linux distributions have therefore released their own advisories in response to the disclosure.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SEC’s ‘Crypto Mom’ Peirce Joins Regent Law Faculty

Longtime SEC Commissioner Hester Peirce, known as "Crypto Mom," will leave the regulator to...

Microsoft unveils AI security tools RAMPART, Clarity

Microsoft has launched two new open-source security tools, RAMPART and Clarity, designed for AI...

OpenAI Readies IPO Filing, Targets September Market Debut

OpenAI is preparing to file for its landmark IPO in the coming days or...

OpenAI IPO planned for September: Wall Street Journal

OpenAI is reportedly targeting a September IPO with Goldman Sachs and Morgan Stanley as...

Institutional Investors Boost MSTR Positions Amid Bitcoin Rally

Thirteen of Strategy's 15 largest institutional shareholders increased their stakes in the company during...

Must Read

7 Best Cryptocurrency Lending Platforms in 2025 (Ranked & Reviewed)

QUICK LINKSOur MethodologyHow to Choose the Best Crypto Lending Platform: Key Factors to ConsiderIn-Depth Reviews of the 7 Best Crypto Lending Platforms1. Nexo -...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading