CISA is warning that a newly-disclosed Linux kernel bug dubbed "CopyFail" is already being exploited, just days after researchers dropped a working root-level exploit. Tracked as CVE-2026-31431, the bug sits in the Linux kernel and gives low-level users a way to take full control of a system by modifying data they should only be able to read, effectively turning limited access into full root privileges on unpatched machines. The issue was disclosed by cybersecurity consultancy Theori, which said the flaw was discovered by its AI-powered penetration testing platform, Xint, and reported to the Linux kernel security team on March 23. Major Linux distributions pushed out patches ahead of public disclosure, which Theori published alongside a proof-of-concept exploit. The Python-based code works against Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16, but the researchers warned that every mainstream Linux kernel built since 2017 is in scope of potential exploitation. "Same script, four distributions, four root shells — in one take. The same exploit binary works unmodified on every Linux distribution," Theori says. That level of reliability has not gone unnoticed. The CISA, the US government's cybersecurity agency, has added the bug to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to patch within two weeks, setting a May 15 deadline. Microsoft backed CISA's findings and said it is already seeing signs of activity follo...
Attackers are cashing in on fresh 'CopyFail' Linux flaw
The Register
·Carly Page
·Published May 5, 2026
·Updated
Affected Software
5 affected components
Linux Kernel
Canonical Ubuntu=24.04
Amazon Linux=2023
Red Hat Enterprise Linux=10.1
SUSE SUSE Linux Enterprise=16
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly-disclosed Linux kernel vulnerability known as 'CopyFail' that is currently being exploited.
2
What security implications are discussed?
The article highlights that the 'CopyFail' vulnerability allows attackers to gain root-level access on affected Linux systems.
3
What is the identifier for the vulnerability?
The vulnerability is tracked as CVE-2026-31431.
4
What products or software are affected by this vulnerability?
The affected software includes the Linux kernel, Canonical Ubuntu 24.04, Amazon Linux 2023, Red Hat Enterprise Linux 10.1, and SUSE Linux Enterprise 16.
5
What action is CISA recommending regarding this vulnerability?
CISA is warning organizations to take immediate action to secure their systems against the 'CopyFail' exploit.