{
  "datePublished": "Thu, 30 Apr 2026 11:25:30 CEST",
  "description": "On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named &#34;Copy Fail&#34;, was publicly disclosed.&lt;br&gt;\nThe vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.&lt;br&gt;\nAs of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.&lt;br&gt;",
  "id": "CERTEU-2026-005",
  "link": "https://cert.europa.eu/publications/security-advisories/2026-005/",
  "source": "certeu",
  "title": "2026-005: High Vulnerability in the Linux Kernel (&#34;Copy Fail&#34;)"
}