The Linux Foundation and security researcher Theori announced a critical vulnerability in the Linux kernel on May 6, 2026. The flaw, designated as CVE-2026-31431, carries the nickname CopyFail. It affects the Linux kernel version 7.0 and all earlier releases.
The vulnerability allows a user with low privileges to escalate their access to root or kernel level. The attack exploits copy failures within specific kernel components. Theori discovered the issue in late March and reported it to the maintainers. Patches were completed a week after the initial report.
The scope of the flaw is exceptionally broad. It impacts almost all major modern Linux distributions. Affected systems include Red Hat Enterprise Linux 10.1, Ubuntu 24.04 LTS, Amazon Linux 2023, SUSE 16, Debian, and Fedora. The CopyFail official website claims that a short Python script can attack all Linux distributions released since 2017.
US federal agencies face a strict deadline to patch affected systems by May 15. The US Cybersecurity and Infrastructure Security Agency issued this order to protect government infrastructure. Operations engineer Yorlin Skrivers Hop stated that the vulnerability affects nearly all major modern Linux distributions. The vulnerability is currently being exploited in the wild, though specific incident reports are not provided.
Theori has not confirmed the exact launch window for all distribution patches. The Linux Foundation continues to coordinate the response across the ecosystem.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.