Copy Fail: Linux Root Escalation
Cloud Security Alliance
pdf
2026-05-03T00:00:00
Abstract
CVE-2026-31431, known as "Copy Fail," is a critical local privilege escalation vulnerability in the Linux kernel's `AF_ALG` cryptographic subsystem affecting major distributions running kernels released since 2017. The flaw allows unprivileged users to gain full root access and escape containers in Kubernetes environments by exploiting a logic error in the kernel's page cache. Because the exploit modifies the in-memory page cache rather than the on-disk files, it is difficult to detect using traditional file integrity monitoring tools.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)