BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Linux “Copy Fail” Bug Lets Local Users Gain Root

  • A critical Linux flaw allows an unprivileged local user to write to a file’s cache and escalate to root privileges.
  • The vulnerability, tracked as CVE-2026-31431, affects nearly all Linux distributions released since 2017.
  • Exploitation is reliable, works across containers, and can be triggered with a small 732-byte Python script.

Cybersecurity researchers from Xint.io and Theori disclosed a high-severity Linux kernel vulnerability on April 30, 2026, which a simple Python exploit can weaponize for full system control. Dubbed Copy Fail, this local privilege escalation flaw is tracked as CVE-2026-31431 with a CVSS score of 7.8.
The issue stems from a logic flaw introduced in a 2017 commit to the kernel’s algif_aead cryptographic module. Consequently, an unprivileged user can write four controlled bytes into the page cache of any readable file. This primitive enables the corruption of a setuid binary like “/usr/bin/su” to gain root access.
Successful exploitation uses a small Python script to trigger the write and execute shellcode. Meanwhile, the vulnerability’s impact is broad, affecting Amazon Linux, RHEL, SUSE, and Ubuntu distributions. The page cache is shared, so the flaw also has cross-container implications.
Researchers compare Copy Fail to the earlier Dirty Pipe vulnerability, noting a similar page cache manipulation goal. However, Copy Fail presents a unique and dangerous combination of traits. According to David Brumley of Bugcrowd, the flaw allows a writable page cache page in an AEAD operation’s scatterlist.
“This vulnerability is unique because it has four properties that almost never appear together: it’s portable, tiny, stealthy, and cross-container,” a Xint.io spokesperson stated. The flaw is reliably triggered without race conditions, making it a significant threat. Linux distributions have therefore released their own advisories in response to the disclosure.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

PayPal Joins Meta’s Muse AI Commerce Ecosystem

Paypal partnered with Meta to bring PayPal checkout to the Muse AI agent, enabling...

US Probes Binance Over Iran Sanctions Violations

The Manhattan US attorney's office and the Justice Department are investigating Binance over potential...

EU central banks drop stablecoin deposit rule for liquidity

The European System of Central Banks (ESCB) proposes replacing mandatory bank-deposit thresholds for stablecoin...

Critical VeloCloud Orchestrator flaw actively exploited

Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as...

Tigress Financial Hikes Google Stock Target to $485

Google stock (NASDAQ: GOOG) opened at $350 Tuesday after a 2.3% rise from $340...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading