Copy Fail Linux Root Exploit
Linux kernel hands root to any local user through a clean page cache overwrite. Theori dropped a working PoC that roots major distros unmodified.
Attackers chain AF_ALG sockets with splice() to trigger a 4-byte out-of-bounds write in authencesn, tainting setuid binaries like su.CVE-2026-31431, CVSS 7.8, disclosed April 29 with public PoC.
Hits kernels from 4.14 to 6.19 across Ubuntu 24.04, RHEL, SUSE, Amazon Linux, Debian. Breaks containers and shared-host CI/CD runners.
732-byte Python script exploits them all using only standard libraries.
