The most severe Linux threat to surface in years catches the world flat-footed
CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.

TL;DR
- Publicly released exploit code for the CopyFail vulnerability (CVE-2026-31431) allows root access on most Linux releases.
- The vulnerability is a local privilege escalation flaw in the kernel's crypto API, exploitable by a single, unmodifiable script.
- CopyFail can compromise multi-tenant systems, Kubernetes containers, CI/CD workflows, and WSL2 instances.
- Few Linux distributions had incorporated patches when the exploit was released, creating a 'zero-day patch gap'.
- Theori researchers discovered the bug using their AI tool, Xint.
- Arch Linux and RedHat Fedora are among the distributions that have patched the vulnerability.
- SUSE, RedHat, and Ubuntu have released mitigation guidance.