[ << ALL_FEED ]

Copy.Fail

More in General

Copy.Fail 🐧

Researchers discovered a bug in the Linux kernel that has existed in systems since 2017 and affects virtually all distributions.

Vulnerability CVE-2026-31431, which we consider trending, consists of four steps:

1️⃣ The user opens an AF_ALG socket and initializes an AEAD algorithm without privileges;

2️⃣ Through splice(), pages of the target file’s cache are transferred into the operation buffer;

3️⃣ An error in authencesn allows writing 4 bytes beyond the buffer boundary directly into the cache pages;

4️⃣ The kernel executes the modified setuid file from the cache → code execution with root privileges.

This vulnerability chain is partially similar to Dirty Pipe (CVE-2022-0847), which also uses system calls:

• pipe — creates a unidirectional data channel;

• splice — allows transferring data between file descriptors without intermediate copying.

Since this vulnerability was already detected in PT Sandbox during software analysis in an Astra Linux image, the exploitation process for the new Copy Fail vulnerability was also detected in PT Sandbox before the public exploit was released.

Thanks to this exploit, it is possible not only to overwrite suid files but also to perform other modifications, making system changes more stealthy.

How to fix 🔧

If you administer Linux systems — update the kernel. The patch is recorded in commit a664bf3d603d. Major distributions have started releasing patched packages since April 29. A reboot will be required after the update.

If an immediate update is not possible — a temporary measure: disable the algif_aead module:


echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf

rmmod algif_aead 2>/dev/null

#cve #tip
@ptescalator

More from global_author

More from global_author

More in General