Copy Fail' vulnerability (CVE-2026-31431)
An unprivileged user can gain root access on major Linux distributions by exploiting CVE-2026-31431, a deterministic 4-byte page cache write bug in the authencesn cryptographic template. The 'Copy Fail' vulnerability (CVE-2026-31431) is a critical logic flaw in the Linux kernel's crypto subsystem disclosed by Xint Code. Unlike previous high-profile kernel exploits that relied on race conditions, Copy Fail is a straight-line logic bug that allows an unprivileged local user to perform a controlled 4-byte write into the page cache of any readable file. This enables an attacker to modify the in-memory version of setuid binaries (like /usr/bin/su) to execute arbitrary shellcode as root without changing the file on disk. Vulnerability affects Linux Kernel version starting 4.14 before 6.18.22.
Microsoft Sentinel (KQL)

