Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

Exploitation of ‘Copy Fail’ Linux Vulnerability Begins

CISA has added the bug to its KEV list, and Microsoft has observed limited exploitation, mainly associated with PoC testing.

Linux vulnerability

Threat actors are exploiting a recently disclosed Linux kernel vulnerability leading to root shell access, the US cybersecurity agency CISA warns.

Tracked as CVE-2026-31431 and dubbed Copy Fail, the security defect lurked for almost a decade, impacting all Linux distributions since 2017.

Affecting the kernel’s authencesn AEAD template, the bug allows authenticated attackers with code execution privileges to modify the cache page of readable setuid-root binaries to elevate privileges to root.

Copy Fail was disclosed on April 29, and CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on Friday, urging federal agencies to patch it within two weeks.

While CISA has not shared details on the observed exploitation, Microsoft said on Friday that it has observed only limited in-the-wild exploitation, mainly surrounding proof-of-concept (PoC) testing.

On the other hand, the tech giant warns that, despite the minimal current activity targeting it, CVE-2026-31431 has broad applicability, and a working PoC exploit has been released, which should raise concern among defenders.

Advertisement. Scroll to continue reading.

“Successful exploitation leads to full root privilege escalation (high impact to confidentiality, integrity, and availability) and could facilitate container breakout, multi-tenant compromise, and lateral movement within shared environments,” Microsoft notes.

“Its reliability, stealth (in-memory-only modification), and cross-platform applicability make it particularly dangerous in cloud, CI/CD, and Kubernetes environments where untrusted code execution is common,” the company says.

Copy Fail, Microsoft warns, can be exploited by any local, unprivileged user, and can be chained with Secure Shell (SSH) access, malicious CI jobs, or access to containers to achieve root shell access.

An attack chain would begin with reconnaissance to identify a container running a vulnerable kernel and continue with the execution of a small script to overwrite in-memory data and elevate privileges.

According to Microsoft, organizations should prioritize identifying potentially vulnerable machines in their environments, apply patches, isolate the systems, apply access controls, and review logs for signs of exploitation.

Related: SonicWall Urges Immediate Patching of Firewall Vulnerabilities

Related: No Patch for New PhantomRPC Privilege Escalation Technique in Windows

Related: Incomplete Windows Patch Opens Door to Zero-Click Attacks

Related: OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.

Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.