Menu

Post image 1
Post image 2
Post image 3
Post image 4
1 / 4
0

New Linux 'Copy Fail' Vulnerability Enables Root Access On Major Distros - Slashdot

it.slashdot.org·it.slashdot.org·about 1 month ago
#xhPriLSj
#comments#modal_box#kernel#linux#cache#newly
Reading 0:00
15s threshold

A newly disclosed Linux kernel flaw dubbed " Copy Fail " can let a local, unprivileged attacker gain root access on major Linux distributions, with researchers claiming the bug affects kernels shipped since 2017. "The POC exploit works out of the box today, but a future version that can escape from containers like Docker is promised soon," writes Slashdot reader tylerni7 . "Technical details are available here ." Slashdot reader BrianFagioli shares a report from NERDS.xyz: A newly disclosed Linux kernel vulnerability called Copy Fail (CVE-2026-31431) allows an unprivileged user to gain root access using a tiny 732-byte script , and it works with unsettling consistency across major distributions. Unlike older exploits that relied on race conditions or fragile timing, this one is a straight-line logic flaw in the kernel's crypto subsystem. It abuses AF_ALG sockets and splice to overwrite a few bytes in the page cache of a target file, such as /usr/bin/su.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More