Back Ground.News Copy Fail Hits Linux: Tiny 4-Byte Flaw Opens Door to Root Access
Copy Fail (CVE-2026-31431) is a Linux kernel vulnerability that allows local unprivileged users to gain root access on affected systems.
Discovered and released this Thursday, the Linux "Copy Fail" fault (CVE-2026-31431) allows a simple local user to obtain complete root access on all major distributions since 2017, without any particular technical expertise.
A serious security vulnerability in the Linux kernel is currently causing a stir: The vulnerability called "Copy Fail" allows local users without special rights to obtain full administrator rights (root access). ( )
Security researchers have disclosed CopyFail, a local privilege escalation (LPE) vulnerability (CVE-2026-31431) in the Linux kernel.
A recently released critical vulnerability in the cryptographic subsystem of the Linux kernel allows full root-level rights expansion. The "Copy Fail" christened vulnerability affects almost all major distributions over the past nine years and can be exploited by a small Python script. The vulnerability under CVE-2026-31431 results from a logic error in the algif_aead module of the kernel crypto API.
Affecting the kernel’s authencesn cryptographic template, the vulnerability was introduced in 2017 and impacts all distributions.
To view factuality data please Upgrade to Premium
To view ownership data please Upgrade to Vantage
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
