Microsoft Warns of Critical Linux 'Copy Fail' Kernel Vulnerability
Microsoft has issued a critical security warning regarding a high-severity vulnerability, identified as CVE-2026-31431 with a CVSS score of 7.8, found within the Linux kernel. Dubbed "Copy Fail," this flaw resides in the cryptographic subsystem's algif_aead module of AF_ALG. It stems from an optimization error where the kernel incorrectly reuses source memory as destination during cryptographic operations, allowing attackers to exploit interactions between the AF_ALG socket interface and the splice() system call. The vulnerability impacts major Linux distributions, including Ubuntu, Red Hat, SUSE, Debian, Fedora, Arch Linux, and Amazon Linux, effectively affecting nearly all non-independent Linux variants. The Cybersecurity and Infrastructure Security Agency (CISA) highlights this as a frequent attack vector posing significant risks to federal enterprises and has mandated that all civilian federal agencies patch affected systems by May 15. Currently, the vulnerability is being actively exploited in the wild. Until official patches are widely deployed, Microsoft advises disabling the affected crypto feature or blocking AF_ALG socket creation to mitigate potential threats. This alert underscores the widespread impact of kernel-level flaws on global infrastructure.
Wire timeline
Microsoft Warns of Critical Linux 'Copy Fail' Kernel Vulnerability
Microsoft has issued a critical security warning regarding a high-severity vulnerability, identified as CVE-2026-31431 with a CVSS score of 7.8, found within the Linux kernel. Dubbed "Copy Fail," this flaw resides in the cryptographic subsystem's algif_aead module of AF_ALG. It stems from an optimization error where the kernel incorrectly reuses source memory as destination during cryptographic operations, allowing attackers to exploit interactions between the AF_ALG socket interface and the splice() system call. The vulnerability impacts major Linux distributions, including Ubuntu, Red Hat, SUSE, Debian, Fedora, Arch Linux, and Amazon Linux, effectively affecting nearly all non-independent Linux variants. The Cybersecurity and Infrastructure Security Agency (CISA) highlights this as a frequent attack vector posing significant risks to federal enterprises and has mandated that all civilian federal agencies patch affected systems by May 15. Currently, the vulnerability is being actively exploited in the wild. Until official patches are widely deployed, Microsoft advises disabling the affected crypto feature or blocking AF_ALG socket creation to mitigate potential threats. This alert underscores the widespread impact of kernel-level flaws on global infrastructure.
Slashdot