Applications
Linux bitten by second severe vulnerability in as many weeks
In April 2026, researchers disclosed CVE-2026-31431 ('Copy Fail'), a highly reliable local privilege escalation vulnerability allowing unprivileged attackers to escalate to root across virtually all m
In April 2026, researchers disclosed CVE-2026-31431 ("Copy Fail"), a highly reliable local privilege escalation vulnerability allowing unprivileged attackers to escalate to root across virtually all major Linux distributions released since 2017. The exploit is a single 732-byte Python script that works unmodified across different distributions. A second severe vulnerability called "Dirty Frag" (CVE-2026-43284 and CVE-2026-43500) was subsequently disclosed, exploiting flaws in the ESP and RxRPC kernel subsystems to enable similar root privilege escalation.
Source: Ars Technica | 2026-05-11