Copy.Fail Linux Vulnerability

2026-05-12T19:23:42Z055d10da6640d306ad45b79773448e7ec9506f3cf0ae09bf92de470a8a4f17c1
AF_ALGPoCTheoricopy.failcross-distrodisclosurefile-integrity-bypasskernellinuxlocal-privilege-escalationno-racepage-cachesplice

What happened

copy.fail (disclosed 29 Apr 2026 by Theori) is a Linux kernel local privilege-escalation that abuses the kernel crypto API (AF_ALG sockets) plus splice() to write four bytes at a time directly into the page cache of arbitrary files the attacker does not own. The attack does not modify on-disk file content (bypassing checksum/AIDE/Tripwire detection), requires no race or per-distro offsets, and works unmodified across Ubuntu, RHEL, Debian, SUSE, Amazon Linux, Fedora and most other distributions. A public working proof-of-concept was released, enabling reliable local root compromise on affected,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
schneier_blog
Record identifier
055d10da6640d306ad45b79773448e7ec9506f3cf0ae09bf92de470a8a4f17c1
Enrichment time
2026-05-12T19:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.