Copy Fail: Linux Root Escalation

Cloud Security Alliance pdf 2026-05-03T00:00:00

Abstract

CVE-2026-31431, known as "Copy Fail," is a critical local privilege escalation vulnerability in the Linux kernel's `AF_ALG` cryptographic subsystem affecting major distributions running kernels released since 2017. The flaw allows unprivileged users to gain full root access and escape containers in Kubernetes environments by exploiting a logic error in the kernel's page cache. Because the exploit modifies the in-memory page cache rather than the on-disk files, it is difficult to detect using traditional file integrity monitoring tools.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD