• News/
  • https://www.theregister.com/2026/05/05/cisa_sounds_the_alarm_on/

Attackers are cashing in on fresh 'CopyFail' Linux flaw

The Register
·
Carly Page
·
Published May 5, 2026
·
Updated

CISA is warning that a newly-disclosed Linux kernel bug dubbed "CopyFail" is already being exploited, just days after researchers dropped a working root-level exploit. Tracked as CVE-2026-31431, the bug sits in the Linux kernel and gives low-level users a way to take full control of a system by modifying data they should only be able to read, effectively turning limited access into full root privileges on unpatched machines. The issue was disclosed by cybersecurity consultancy Theori, which said the flaw was discovered by its AI-powered penetration testing platform, Xint, and reported to the Linux kernel security team on March 23. Major Linux distributions pushed out patches ahead of public disclosure, which Theori published alongside a proof-of-concept exploit. The Python-based code works against Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16, but the researchers warned that every mainstream Linux kernel built since 2017 is in scope of potential exploitation. "Same script, four distributions, four root shells — in one take. The same exploit binary works unmodified on every Linux distribution," Theori says. That level of reliability has not gone unnoticed. The CISA, the US government's cybersecurity agency, has added the bug to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to patch within two weeks, setting a May 15 deadline. Microsoft backed CISA's findings and said it is already seeing signs of activity follo...

Read full article

Affected Software

5 affected components
Linux Kernel
Canonical Ubuntu=24.04
Amazon Linux=2023
Red Hat Enterprise Linux=10.1
SUSE SUSE Linux Enterprise=16
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly-disclosed Linux kernel vulnerability known as 'CopyFail' that is currently being exploited.

2

What security implications are discussed?

The article highlights that the 'CopyFail' vulnerability allows attackers to gain root-level access on affected Linux systems.

3

What is the identifier for the vulnerability?

The vulnerability is tracked as CVE-2026-31431.

4

What products or software are affected by this vulnerability?

The affected software includes the Linux kernel, Canonical Ubuntu 24.04, Amazon Linux 2023, Red Hat Enterprise Linux 10.1, and SUSE Linux Enterprise 16.

5

What action is CISA recommending regarding this vulnerability?

CISA is warning organizations to take immediate action to secure their systems against the 'CopyFail' exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Attackers are cashing in on fresh 'CopyFail' Linux flaw - SecAlerts