2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.
CSIRTS triage
- What
- The vulnerability allows for local privilege escalation due to a flaw in the kernel's functionality.
- Who is affected
- Every mainstream Linux distribution shipping a kernel built since 2017 is affected.
- Urgency
- Remediation is urgent as a public proof-of-concept exploit is available and no fixed kernel package has been shipped yet.
- Action
- Apply the interim mitigation immediately, prioritizing Kubernetes nodes and CI/CD runners.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Linux Kernel
Get an email when a new Linux Kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cert.europa.eu/publications/security-advisories/2026-005/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-31431Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-31431 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
- unknownexploitedOngoing updates on Copy.fail and variantsaws
- unknownexploitedDirty Frag and other issues in Amazon Linux kernelsaws
- unknownexploitedCVE-2026-31431aws
- unknownexploitedMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)cert-fr-avis
- highexploited[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rightscert-bund
- highexploitedCVE-2026-31431: crypto: algif_aead - Revert to operating out-of-placemsrc
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- unknownexploitedSiemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- criticalexploitedABB Ability Edgeniuscisa
- unknownexploitedUSN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilitiesubuntu
More from CERT-EU Security Advisories
- critical2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway2026-08-19
- critical2026-009: Critical Vulnerabilities in Microsoft SharePoint2026-07-23
- critical2026-008: Critical vulnerabilities in Ivanti Sentry2026-06-10
- critical2026-007: Critical Vulnerability in Windows Netlogon2026-06-10
- critical2026-006: Critical Vulnerability in PAN-OS2026-05-06