CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments

2026-05-04T14:52:23Zd61c18c959df420c796ff31fcd08baeddd7e766a1e8b18d9e0c9b9a9a3c9a14b
CVE-2026-31431cloudcontainerscopy faildetectionexploit-in-the-wildkernelkuberneteslinuxmicrosoft-security-blogmitigationpatchingprivilege escalationroot

What happened

Microsoft Security Blog reports CVE-2026-31431 (“Copy Fail”), a high-severity Linux vulnerability that enables local root privilege escalation across cloud environments, containerized/Kubernetes workloads, and host systems. A working exploit is observed in the wild; organizations are advised to urgently detect and mitigate attacks, apply vendor/kernel patches, harden container hosts, monitor relevant telemetry, and follow Microsoft’s remediation guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
d61c18c959df420c796ff31fcd08baeddd7e766a1e8b18d9e0c9b9a9a3c9a14b
Enrichment time
2026-05-04T14:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.