2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

Imported from official source

Advisory

Cybersecurity Classified by Officially

High Vulnerability in the Linux Kernel ("Copy Fail")

  • 29/04/2026 --- v1.0 -- Initial publication
  • On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed [1].

    The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.

    As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.

    The vulnerability CVE-2026-31431, with a CVSS score of 7.8, is a local privilege escalation flaw in the Linux kernel's algif_aead module, the AEAD socket interface of the kernel's userspace crypto API (AF_ALG). The flaw originates from an in-place optimisation introduced in 2017 (commit 72548b093ee3), which allows page-cache pages to be placed into a writable destination scatterlist. By chaining an AF_ALG socket operation with splice(), an unprivileged local user can perform a controlled 4-byte write to an arbitrary page-cache-backed page, targeting a setuid binary such as /usr/bin/su to obtain a root shell [1].

    The upstream fix is mainline commit a664bf3d603d, which reverts the 2017 optimisation. It was committed on 1 April 2026 [1].

    The vulnerability affects every mainstream Linux distribution shipping a kernel built between 2017 and the availability of the patch. The following distributions were directly verified by the researchers [1]:

    Other distributions running kernels in the affected range are implicitly affected, including Debian, Arch Linux, Fedora, Rocky Linux, AlmaLinux, Oracle Linux, and embedded Linux distributions.

    Patch availability by distribution (as of 30 April 2026):

    This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-005/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    2 versions recorded. The original is kept in full — nothing is overwritten.

    1. v2 imported change on current
    2. v1 as first published on

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    2 recorded
    Identity
    security-advisories-10942

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.