Copy Fail: Critical Linux Kernel Vulnerability CVE-2026-31431 Disclosed
Researchers have disclosed a critical local privilege escalation vulnerability, CVE-2026-31431, nicknamed Copy Fail, affecting the Linux kernel. Discovered via AI-assisted analysis, this deterministic logic flaw resides in the algif_aead module of the AF_ALG interface. It allows unprivileged attackers to gain root access by writing four controlled bytes into the system's file page cache, bypassing integrity checks because physical disk files remain unchanged. The vulnerability impacts millions of systems running mainstream distributions like Ubuntu, Red Hat, and Debian, specifically kernels versions 4.14 through 6.19.12. A simple 732-byte Python script can exploit this flaw across different distributions without modification. This poses severe risks for cloud environments, enabling Kubernetes container breakouts and multi-tenant host compromises. Palo Alto Networks' Unit 42 urges immediate patching with vendor-issued kernel updates. If patching is not immediately feasible, disabling the vulnerable module is recommended as an interim mitigation. The flaw stems from a 2017 optimization error combined with earlier algorithm additions, highlighting significant security implications for Linux-based infrastructure worldwide.
Wire timeline
Copy Fail: Critical Linux Kernel Vulnerability CVE-2026-31431 Disclosed
Researchers have disclosed a critical local privilege escalation vulnerability, CVE-2026-31431, nicknamed Copy Fail, affecting the Linux kernel. Discovered via AI-assisted analysis, this deterministic logic flaw resides in the algif_aead module of the AF_ALG interface. It allows unprivileged attackers to gain root access by writing four controlled bytes into the system's file page cache, bypassing integrity checks because physical disk files remain unchanged. The vulnerability impacts millions of systems running mainstream distributions like Ubuntu, Red Hat, and Debian, specifically kernels versions 4.14 through 6.19.12. A simple 732-byte Python script can exploit this flaw across different distributions without modification. This poses severe risks for cloud environments, enabling Kubernetes container breakouts and multi-tenant host compromises. Palo Alto Networks' Unit 42 urges immediate patching with vendor-issued kernel updates. If patching is not immediately feasible, disabling the vulnerable module is recommended as an interim mitigation. The flaw stems from a 2017 optimization error combined with earlier algorithm additions, highlighting significant security implications for Linux-based infrastructure worldwide.
Unit 42