Vulnerability Watch

Forum Discussion

scaveza's avatar
scaveza
Product Team
10 hours ago

FAQ on Copy Fail Linux Kernel Privilege Escalation (CVE-2026-31431)

On April 29, researchers at Theori publicly disclosed CVE-2026-31431, a local privilege escalation vulnerability in the Linux kernel's cryptographic subsystem dubbed "Copy Fail." The flaw has been present in every major Linux distribution since 2017. A public proof-of-concept exploit is available and reported to work reliably, drawing comparisons to Dirty Cow and Dirty Pipe.

CVE

Description

CVSSv3

CVE-2026-31431

Linux Kernel Local Privilege Escalation Vulnerability

7.8

Patched kernel versions are available, though some major distributions have not yet shipped updates.

For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply