News.Ycombinator Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
Article Content
- •CVE-2026-31431 allows local users to gain root access on Linux systems since 2017.
- •The exploit is a 732-byte Python script that modifies the page cache without altering the disk file.
- •Patches are available, and immediate updates are recommended for affected distributions.
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017. The exploit, which is a 732-byte Python script, modifies the page cache of any readable file without altering the on-disk version, making it stealthy and difficult to detect. Discovered by Theori researcher Taeyang Lee using AI-assisted tools, the flaw stems from a logic error in the kernel's cryptographic subsystem, specifically within the algif_aead module. Patches were made available on April 1, 2026, following the initial disclosure on March 23, 2026, with public proof-of-concept released on April 30, 2026. The vulnerability poses a significant risk, especially in multi-tenant environments like cloud services and Kubernetes, where it can enable container escapes. Security teams are urged to apply patches immediately to mitigate risks associated with this critical flaw.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (228)
Following this threat?
Track Fedora and CVE-2016-5195 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…