certeu-2026-005

certeu
Description

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed.<br> The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.<br> As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.<br>

Timeline
Published
Thu, 30 Apr 2026 11:25:30 CEST
Last Modified
Thu, 30 Apr 2026 11:25:30 CEST
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "datePublished": "Thu, 30 Apr 2026 11:25:30 CEST",
  "description": "On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed.<br>\nThe vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.<br>\nAs of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.<br>",
  "id": "CERTEU-2026-005",
  "link": "https://cert.europa.eu/publications/security-advisories/2026-005/",
  "source": "certeu",
  "title": "2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")"
}
View JSON API Download JSON