Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years
PoC publicLinux kernel (AF_ALG/algif_aead) Read at Palo Alto Unit 42
Below is the opening; the full story is at Palo Alto Unit 42.
From Palo Alto Unit 42
Executive Summary
On April 29, 2026, researchers publicly disclosed a highly reliable local privilege escalation (LPE) vulnerability tracked as CVE-2026-31431">CVE-2026-31431. This vulnerability is commonly referred to as Copy Fail. Discovered in about an hour through an AI-assisted process, this logic flaw allows an unprivileged local attacker to consistently escalate their access to root across virtually all major Linux distributions released since 2017.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.