This critical Linux vulnerability is putting millions of systems at risk - how to protect yours
Summary
A critical Linux kernel vulnerability, CVE-2026-31431 aka "Copy Fail," lets an attacker with basic access alter four bytes in the kernel page cache to escalate privileges to root. The flaw abuses the AF_ALG socket interface and splice() and affects kernels from 4.14 through 6.19.12, making it easy to exploit without timing or race conditions. Researchers at Theori and Xint Code (using AI-assisted analysis) identified the issue and flagged it as highly severe. Mitigate by updating to a patched kernel, verify the algif_aead module status with the provided command, or disable the module if a patch is not yet applied.
Classifications
industries
No industries detected
applications
No applications detected
AskAI Classifications
Labels
No AI classifications detected