HomeSecurityCopy Fail: Linux vulnerability allows root access to systems

Copy Fail: Linux vulnerability allows root access to systems

A vulnerability in Linux exposes a new local privilege escalation (LPE) mechanism that could allow an unprivileged user to gain full system control. The vulnerability, tracked as CVE-2026-31431, is considered quite severe (CVSS 7.8) and is known by the codename Copy Fail.

Copy Fail Linux

What is Copy Fail and why is it a concern?

According to researchers at Xint.io and Theori, the vulnerability allows a local unprivileged user to write controlled bytes to the page cache of any readable file on a Linux system. This method could allow the modification of critical binaries and ultimately gain root privileges.

The problem is traced to a logic flaw in the cryptographic subsystem of the Linux kernel , specifically in the algif_aead. The vulnerability appears to have been introduced in 2017, which means it affects a wide range of Linux versions and distributions released since then.

See also: Vulnerability in Ubuntu Kernel allows Root access

How the exploitation of the vulnerability works

Exploiting the vulnerability does not require complex techniques or special tools. Instead, the researchers demonstrated that a simple Python script of just 732 bytes is enough to carry out the attack.

The process involves creating an  AF_ALG socket, binding to specific cryptographic algorithms, constructing shellcode, and modifying a setuid binary such as “/usr/bin/su.” Then, through the execution of the execve, the malicious payload is loaded and executed with root privileges.

What makes the attack particularly dangerous is that it does not require race conditions or complex circumvention techniques.

Copy Fail: Linux vulnerability allows root access to systems

Impact on all major Linux distributions

The vulnerability affects almost all popular Linux distributions released after 2017, including Amazon Linux, RHEL, SUSE , and Ubuntu. Vendors have already issued warnings and security updates, urging system administrators to upgrade immediately.

See also: Vulnerability in Linux battery tool allows changing system settings

An additional concern is that the attack could also have an impact on container, as the page cache is shared between processes on the same system. This means that a user in a container could potentially affect other isolated processes.

Similarities with Dirty Pipe and new data

Copy Fail has significant similarities to the CVE-2022-0847, known as Dirty Pipe, which has caused a lot of concern in the security community. In both cases, an attacker can inject data into the file page cache.

However, the new vulnerability is considered even more dangerous, as it relies on a different subsystem and is more reliable to exploit. As experts explain, a specific optimization introduced in 2017 allows unprivileged processes to exploit the splice() to write data to files that do not belong to them.

Why Copy Fail is considered so dangerous

Experts point out that the vulnerability stands out due to a rare combination of features: it is portable, works on many distributions, requires minimal code, and can be executed without leaving any visible traces. In addition, it allows bypassing isolation mechanisms such as sandboxes, which significantly increases the risk in modern cloud infrastructures.

See also: CrackArmor: 9 vulnerabilities in Linux AppArmor allow root escalation

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The ability of a single user to gain full administrative privileges on a system is a critical threat, especially in environments where multiple users or services share the same infrastructure.

Copy Fail: Linux vulnerability allows root access to systems

What should system administrators do?

Prompt installation of security updates is the most basic protection measure. In addition, it is recommended to limit access to local users, monitor suspicious activity, and strengthen isolation mechanisms.

The incident is a reminder that even mature and widely used systems like Linux can hide critical bugs for years. Continuous monitoring and rapid response to new vulnerabilities remain key factors in ensuring cybersecurity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS