{"id":425416,"date":"2026-04-30T15:58:12","date_gmt":"2026-04-30T15:58:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/425416\/"},"modified":"2026-04-30T15:58:12","modified_gmt":"2026-04-30T15:58:12","slug":"linux-copy-fail-flaw-delivers-root-level-access-to-distros","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/425416\/","title":{"rendered":"Linux &#8216;Copy Fail&#8217; Flaw Delivers Root-Level Access to Distros"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.bankinfosecurity.com\/artificial-intelligence-machine-learning-c-469\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Artificial Intelligence &amp; Machine Learning<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/governance-risk-management-c-93\" id=\"asset_topic_1_2\" rel=\"nofollow noopener\" target=\"_blank\">Governance &amp; Risk Management<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/next-generation-technologies-secure-development-c-467\" id=\"asset_topic_1_3\" rel=\"nofollow noopener\" target=\"_blank\">Next-Generation Technologies &amp; Secure Development<\/a>\n                                                                                                <\/p>\n<p>                    AI-Assisted Offensive Security Researcher Discovered Flaw After 1 Hour of Scanning<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/mathew-j-schwartz-i-892\" rel=\"nofollow noopener\" target=\"_blank\">Mathew J. Schwartz<\/a> (<a href=\"https:\/\/www.twitter.com\/euroinfosec\" rel=\"nofollow noopener\" target=\"_blank\">euroinfosec<\/a>)                                                    \u2022<br \/>\n                        April 30, 2026 \u00a0 \u00a0 <a href=\"#disqus_thread\"\/><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/04\/linux-copy-fail-flaw-delivers-root-level-access-to-distros-image_large-2-a-31558.jpg\" alt=\"Linux 'Copy Fail' Flaw Delivers Root-Level Access to Distros\" class=\"img-responsive \"\/><br \/>\n                Image: Shutterstock            <\/p>\n<p>The Linux kernel needs to be patched to fix a vulnerability that exists in every distribution of the operating system created from 2017, onward. Successfully exploiting the flaw in the kernel&#8217;s cryptography API would give an attacker root-level access to the operating system. <\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/ai-agents-introduce-new-insider-threat-model-a-31525?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">AI Agents Introduce a New Insider Threat Model<\/a><\/p>\n<p>&#8220;An unprivileged local user can write 4 controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root,&#8221; <a href=\"https:\/\/copy.fail\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> researchers at offensive security firm Theori on Wednesday of the local privilege escalation flaw, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-31431\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-31431<\/a>. They nicknamed it &#8220;Copy Fail.&#8221;<\/p>\n<p>&#8220;Most major distributions are shipping the fix now,&#8221; they said. As a temporary mitigation, users can &#8220;disable the algif_aead module&#8221; to block the flaw from being exploited, although potentially at the cost of some functionality, they said. <\/p>\n<p>The module is part of the Linux kernel&#8217;s cryptographic subsystem, and typically ships active by default.<\/p>\n<p>Theori <a href=\"https:\/\/github.com\/theori-io\/copy-fail-CVE-2026-31431\" target=\"_blank\" rel=\"nofollow noopener\">released<\/a> a proof-of-concept exploit. Other researchers have also <a href=\"https:\/\/x.com\/rootsecdev\/status\/2049657419505017206\" target=\"_blank\" rel=\"nofollow\">published<\/a> their own scripts.<\/p>\n<p>The risk posed by the flaw is serious, security experts said. &#8220;If you described this bug to a top kernel researcher &#8211; give me a universal Linux LPE, works across major distributions, no race window, no per-kernel offsets, clean container-escape primitive &#8211; they probably wouldn&#8217;t give you a timeline. They&#8217;d tell you this is the kind of thing that, when it exists at all, tends to sell on the broker market for the price of a house,&#8221; <a href=\"https:\/\/www.bugcrowd.com\/blog\/what-we-know-about-copy-fail-cve-2026-31431\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> David Brumley, chief artificial intelligence and science officer at bug bounty firm Bugcrowd, in a blog post.<\/p>\n<p>The biggest risk posed by the new vulnerability is to any environment that runs &#8220;multi-tenant Linux, shared-kernel containers, CI runners that execute untrusted code or anything where someone you don&#8217;t fully trust can execve&#8221; &#8211; aka run applications &#8211; &#8220;as a regular user,&#8221; Theori researchers said. <\/p>\n<p>They see a &#8220;medium&#8221; risk for stand-alone Linux servers, and &#8220;low&#8221; risk for anyone running a &#8220;single-user laptop with full-disk encryption and a locked screen.&#8221; Regardless, their advice is to &#8220;patch anyway.&#8221;<\/p>\n<p>The vulnerability carries a CVSS base score of 7.8, which ranks as &#8220;high.&#8221; <\/p>\n<p>Bugcrowd&#8217;s Brumley said: &#8220;Don&#8217;t be fooled by the &#8216;high&#8217; &#8211; not critical &#8211; CVSS score. If your stack runs untrusted code and the isolation story has the word &#8216;container&#8217; in it without the word &#8216;microVM,&#8217; &#8216;gVisor,&#8217; or &#8216;dedicated host&#8217; right after it, Copy Fail is in your threat model.&#8221; Don&#8217;t assume Linux containers that can run untrusted code remain safe, he said.<\/p>\n<p>AI-Assisted Bug Discovery<\/p>\n<p>The flaw is the latest to be found by researchers using the latest AI tools for scanning code (see: <a href=\"https:\/\/www.bankinfosecurity.com\/blogs\/bug-management-in-mythos-era-assume-youre-unpatched-p-4091\" rel=\"nofollow noopener\" target=\"_blank\">Bug Management in the Mythos Era: &#8216;Assume You&#8217;re Unpatched&#8217;<\/a>). <\/p>\n<p>Theori said one of its researchers discovered the flaw, assisted by an AI tool, when &#8220;studying how the Linux crypto subsystem interacts with page-cache-backed data.&#8221; The researcher used Theori&#8217;s in-house large language model, which the firm describes as being an AI-powered, LLM-native security analysis tool developed for scanning source code, configuration files and binaries for vulnerabilities. <\/p>\n<p>Finding the vulnerability took about one hour of time to scan &#8220;the Linux crypto\/subsystem,&#8221; and involved no &#8220;harnessing,&#8221; meaning no agents or wraparounds.<\/p>\n<p>As tools improve, much less experienced researchers may be able to achieve similar results. &#8220;Copy Fail is not a story about a single bug, or about one team&#8217;s tooling. It&#8217;s a data point that the cost of finding deep logic flaws may have dropped by something like an order of magnitude,&#8221; Brumley said.<\/p>\n<p>Detecting Exploit Attempts<\/p>\n<p>One upside for defenders is that attempts to exploit this flaw can be noisy, provided they have the right observability. <\/p>\n<p>Cybersecurity consultancy Threatbear recommends using the Linux kernel Extended Berkeley Packet Filter technology to watch for unexpected attempts to create the required socket connection &#8211; known as AF_ALG &#8211; that touches kernel memory, which would normally not be direct but instead handled using a user space library such as OpenSSL. <\/p>\n<p>&#8220;The core mechanism of this vulnerability involves the kernel doing a temporary &#8216;scratch write&#8217; of a sequence number during the crypto operation. That scratch write is strictly limited to 4 bytes,&#8221; it <a href=\"https:\/\/www.threatbear.co\/blog\/detecting-copyfail-using-ebpf\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a>.<\/p>\n<p>Since most root shell payloads would require about 160 bytes of assembly code, the attacker needs to do the attack in stages. &#8220;They have to trigger the vulnerability, write 4 bytes, trigger the vulnerability again, write the next 4 bytes and so on, inching their way through the file cahe,&#8221; Threatbear said.<\/p>\n<p>When viewed with eBPF, such socket connection attempts from unexpected scripts should be a &#8220;glowing red flag&#8221; that an attack is in progress, it said.<\/p>\n<p>            <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Artificial Intelligence &amp; Machine Learning , Governance &amp; Risk Management , Next-Generation Technologies &amp; Secure Development AI-Assisted Offensive&hellip;\n","protected":false},"author":2,"featured_media":425417,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[186036,4061,3312,186035,61,14336,60,37028,80],"class_list":["post-425416","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-cryptgraphy","tag-crypto","tag-cybersecurity","tag-distro","tag-ie","tag-information-security","tag-ireland","tag-linux","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/425416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=425416"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/425416\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/425417"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=425416"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=425416"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=425416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}