< Back to all clusters
[TECHNOLOGY] · 5 sources

CopyFail Linux kernel flaw enables local root escalation across major distributions

A newly disclosed Linux kernel vulnerability, identified as CVE‑2026‑31431 and dubbed “CopyFail”, allows a local attacker with limited privileges to obtain root access. The flaw resides in the kernel’s cryptographic API and does not rely on specific memory conditions, making exploitation more reliable across versions.

The issue was reported to the Linux kernel security team five weeks before public disclosure. While patches have been released for kernel branches from 5.10 to 7.0, many distributions have not yet rolled out the fixes. Debian, Arch, Fedora, SUSE and Amazon Linux have issued updates or advisories, whereas Ubuntu advises users to apply mitigations and restart to load a patched kernel when available.

Because the exploit works after an attacker gains limited code execution—such as via a compromised web service, container, or CI/CD job—it expands the attack surface beyond initial breach points. Administrators are urged to update their kernels promptly and apply distribution‑specific mitigations to close the window of exposure.