certeu-2026-005
certeuOn 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed.<br> The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.<br> As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.<br>
- Published
- Thu, 30 Apr 2026 11:25:30 CEST
- Last Modified
- Thu, 30 Apr 2026 11:25:30 CEST
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"datePublished": "Thu, 30 Apr 2026 11:25:30 CEST",
"description": "On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed.<br>\nThe vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released.<br>\nAs of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.<br>",
"id": "CERTEU-2026-005",
"link": "https://cert.europa.eu/publications/security-advisories/2026-005/",
"source": "certeu",
"title": "2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")"
}