Switch language한국어
Back to the list

CISA flags actively exploited ‘Copy Fail’ Linux kernel flaw enabling root takeover across major distros — unpatched systems may remain vulnerable to attack

TL;DR AI

Key summary

2 min read
  1. CISA says CVE-2026-31431, a Linux kernel privilege-escalation bug nicknamed Copy Fail, is being actively exploited.

  2. The agency added the flaw to its Known Exploited Vulnerabilities catalog and urged rapid patching by federal agencies and other organizations.

  3. The issue affects the kernel’s algif_aead interface and has a public working exploit that can lead to root on major Linux distributions.

  4. Impacted systems include Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16, raising risk for unpatched hosts.

Read the original