Industry
The most severe Linux threat to surface in years catches the world flat-footed
CVE-2026-31431 ('Copy Fail'), a high local privilege escalation vulnerability in the Linux kernel, was publicly disclosed on April 29, 2026, affecting every mainstream Linux distribution shipping kern
CVE-2026-31431 ("Copy Fail"), a high local privilege escalation vulnerability in the Linux kernel, was publicly disclosed on April 29, 2026, affecting every mainstream Linux distribution shipping kernels built since 2017. A simple 732-byte Python script can exploit the vulnerability to obtain root access on essentially all Linux distributions shipped since 2017. As of the advisory date, no distribution had shipped a fixed kernel package, though the mainline fix was committed on April 1, 2026, with vendor updates still pending.
Source: Ars Technica | 2026-04-30