Copy.Fail

More in General
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- ⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered…
Copy.Fail 🐧
Researchers discovered a bug in the Linux kernel that has existed in systems since 2017 and affects virtually all distributions.
Vulnerability CVE-2026-31431, which we consider trending, consists of four steps:
1️⃣ The user opens an AF_ALG socket and initializes an AEAD algorithm without privileges;
2️⃣ Through splice(), pages of the target file’s cache are transferred into the operation buffer;
3️⃣ An error in authencesn allows writing 4 bytes beyond the buffer boundary directly into the cache pages;
4️⃣ The kernel executes the modified setuid file from the cache → code execution with root privileges.
This vulnerability chain is partially similar to Dirty Pipe (CVE-2022-0847), which also uses system calls:
• pipe — creates a unidirectional data channel;
• splice — allows transferring data between file descriptors without intermediate copying.
Since this vulnerability was already detected in PT Sandbox during software analysis in an Astra Linux image, the exploitation process for the new Copy Fail vulnerability was also detected in PT Sandbox before the public exploit was released.
Thanks to this exploit, it is possible not only to overwrite suid files but also to perform other modifications, making system changes more stealthy.
How to fix 🔧
If you administer Linux systems — update the kernel. The patch is recorded in commit a664bf3d603d. Major distributions have started releasing patched packages since April 29. A reboot will be required after the update.
If an immediate update is not possible — a temporary measure: disable the algif_aead module:
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf
rmmod algif_aead 2>/dev/null
#cve #tip
@ptescalator
More in General
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- ⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered…






