The most severe Linux threat to surface in years catches the world flat-footed

CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.

The most severe Linux threat to surface in years catches the world flat-footed

TL;DR

  • Publicly released exploit code for the CopyFail vulnerability (CVE-2026-31431) allows root access on most Linux releases.
  • The vulnerability is a local privilege escalation flaw in the kernel's crypto API, exploitable by a single, unmodifiable script.
  • CopyFail can compromise multi-tenant systems, Kubernetes containers, CI/CD workflows, and WSL2 instances.
  • Few Linux distributions had incorporated patches when the exploit was released, creating a 'zero-day patch gap'.
  • Theori researchers discovered the bug using their AI tool, Xint.
  • Arch Linux and RedHat Fedora are among the distributions that have patched the vulnerability.
  • SUSE, RedHat, and Ubuntu have released mitigation guidance.