Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

Children sketch new inventions and eavesdrop on germs at EU science fair in Brussels

New Linux ‘copy failure’ vulnerability allows root access on major distributions

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New Linux ‘copy failure’ vulnerability allows root access on major distributions
Identity

New Linux ‘copy failure’ vulnerability allows root access on major distributions

By April 30, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 30, 2026Linux / Vulnerabilities

Cybersecurity researchers have revealed details of a Linux local privilege escalation (LPE) flaw that could allow unprivileged local users to gain root.

This high-severity vulnerability, tracked as CVE-2026-31431 (CVSS score: 7.8), has been codenamed Copy Fail by Xint.io and Theori.

“An unprivileged local user can write a controlled 4 bytes to the page cache of a readable file on a Linux system and use it to gain root,” the Xint.io and Theori vulnerability research team said.

The core of this vulnerability is due to a logical flaw in the Linux kernel’s cryptographic subsystem, specifically the algif_aead module. This issue was introduced in a source code commit made in August 2017.

Successful exploitation of this flaw could allow a simple 732-byte Python script to edit a setuid binary and gain root on almost any Linux distribution shipped since 2017, including Amazon Linux, RHEL, SUSE, and Ubuntu. The Python exploit involves four steps.

Open the AF_ALG socket and bind to authencesn(hmac(sha256),cbc(aes)). Build the shellcode payload. Triggers a write operation to the kernel’s cached copy of ‘/usr/bin/su’. Call execve(“/usr/bin/su”) to load the injected shellcode and run it as root.

Although this vulnerability cannot be exploited independently and remotely, a local unprivileged user can gain root simply by corrupting the page cache of a setuid binary. The same primitives also have cross-container implications because the page cache is shared by all processes on the system.

In response to this disclosure, Linux distributions released their own advisories.

The copy failure is mirrored in another Linux kernel LPE vulnerability, Dirty Pipe (CVE-2022-0847), which allows an unprivileged user to combine data into the page cache of read-only files and ultimately overwrite sensitive files on the system and potentially execute code.

“Copy failures are primitives of the same class in different subsystems,” said David Brumley of Bugcrowd. “A 2017 in-place optimization in algif_aead allows page cache pages to enter the kernel’s writable destination scatter list for AEAD operations sent over an AF_ALG socket. An unprivileged process can then dispatch a splice() to that socket and complete a small, targeted write to the page cache for a file it does not own.”

What makes this vulnerability dangerous is that it can be triggered reliably and does not require a race condition or kernel offset. Additionally, the same exploit works across distributions.

“This vulnerability is unique because it has four characteristics that rarely appear together: portability, small size, stealth, and cross-container nature,” a Xint.io spokesperson told The Hacker News in a statement. “This enhances the privileges of all user accounts, no matter how low-level, to full administrative access. It also allows sandboxing to be bypassed and works on all Linux versions and distributions.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA global research partner for Europe’s most pressing challenges
Next Article Children sketch new inventions and eavesdrop on germs at EU science fair in Brussels

Related Posts

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

April 30, 2026

Google fixes issue with CVSS 10 Gemini CLI CI RCE and cursor flaw that could allow code execution

April 30, 2026

SAP-related npm packages compromised in supply chain attack that steals credentials

April 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

Children sketch new inventions and eavesdrop on germs at EU science fair in Brussels

New Linux ‘copy failure’ vulnerability allows root access on major distributions

A global research partner for Europe’s most pressing challenges

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.