Copy.Fail Linux Vulnerability
2026-05-13T07:23:54Z•c52a68e4432491497ca65c64ad52acbaea8f0d725478ead41918a1f653fff0b9
AF_ALGAIDECVE-2026-31431Tripwirecopy.failcross-distrodetection-evasionfile-integritykernellinuxlocal-privilege-escalationpage-cachepoCsplice
What happened
Copy.Fail (disclosed 29 Apr 2026 by Theori, tracked as CVE-2026-31431) is a Linux-kernel local privilege-escalation vulnerability that abuses the kernel crypto API (AF_ALG sockets) together with splice() to write four bytes at a time directly into the page cache of files the attacker does not own. The exploit works unmodified across Ubuntu, RHEL, Debian, SUSE, Amazon Linux, Fedora and most other distributions, requires no race condition or per-distro offsets, and has a public working PoC. Because the on-disk file contents are not modified, checksum- and snapshot-based integrity tools (AIDE, Tr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- schneier_blog
- Record identifier
- c52a68e4432491497ca65c64ad52acbaea8f0d725478ead41918a1f653fff0b9
- Enrichment time
- 2026-05-13T07:23:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.