Copy Fail gives local users root on most Linux systems
A high-severity local privilege escalation vulnerability affecting most major Linux distributions has been disclosed. The flaw, named "Copy Fail", is tracked as CVE-2026-31431 with a CVSS score of 7.8. By exploiting a logic flaw in the kernel crypto subsystem, attackers can write controlled bytes into the page cache of setuid binaries, allowing an unprivileged user to gain root. The issue has been present since a code change in 2017. Unlike earlier variants, it requires neither race conditions nor precise timing, and proof-of-concept code has been published as a Python script of roughly 700 bytes. A workaround is to disable the algif_aead kernel module.
What this means for your organisation
This is not the front door but the staircase. The value to an attacker lies in what follows the first foothold: a compromised web application, a stolen SSH key or an insider becomes full control of the server. When exploitation is simple, reliable and already public, your window is short. Shared servers and machines where several users hold shell accounts are the first place to look.
Berigo recommends
- Apply distribution updates as soon as they are available, prioritising multi-user servers.
- Disable the algif_aead kernel module as an interim measure where patches lag, after testing the impact.
- Review who actually holds local shell access on production servers, and remove what is not needed.
- Ensure server logs are shipped somewhere an attacker with root cannot alter them.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch