#copyfail
36 posts · Last used May 21
EVERYONE GETS AN LPE
Windows:
#BlueHammer (#CVE_2026_33825)
#RedSun (#CVE_2026_41091)
#UnDefend (#CVE_2026_45498)
#WindowsInstaller (#CVE_2026_27910):
Linux:
#CopyFail (#CVE_2026_31431)
#SSHKeysignPwn (#CVE_2026_46333)
FreeBSD:
#FatGid (#CVE_2026_45250)
#ExecveBug (#CVE_2026_7270)
#LPE — Local Privilege Escalation. A class of vulnerabilities that need a local user account on the target machine to reach higher levels of privilege, up to superuser/root
#RCE — Remote Code Execution. A class of vulnerabilities that can be exploited over unprivileged network connections, giving the attacker privileged access to the target machine.
#CopyFail, #DirtyFrag are LPEs that affect Linux systems. LPEs are typically harder to exploit than RCEs.
Hope this helps to avoid Clickbait.
Yk all these recent exploits are a sad thing for itanium users cause now the latest Linux itsnium kernel has 2 huge vulnerabilities and I wish I could do something but well I don't actually own any itanium hardware wich is embarrassing.
#Linux #itanium #copyfail #dirtyfrag
Oh good, another high-severity #Linux #security vulnerability that somebody botched the disclosure of, turning it into a high-severity zero-day.
Because #CopyFail wasn't bad enough. Now we've got #DirtyFrag too.
Can #cybersecurity people please stop botching vulnerability disclosure? Thanks.
https://github.com/V4bel/dirtyfrag/blob/master/README.md
#security
#OpenShift hosters 🔊 Red Hat has released blocker for copy-fail vulnerability, no reboots needed:
https://access.redhat.com/solutions/7142136
#RedHat #CopyFail #CVE202631431
CVE-2026-31431, dubbed "Copy Fail," is a high-severity Linux kernel flaw (CVSS 7.8) actively exploited in the wild. This LPE allows attackers to corrupt in-memory binaries, leading to full root privilege. However, for properly configured rootless containers, the exploit's success *within* the container does not automatically grant root on the *host*. Learn the critical distinction.
https://www.tpp.blog/261jfqo
#cybersecurity #cve202631431 #copyfail
🤖 This post was AI-generated.
Red Hat product updates to copy fail available https://access.redhat.com/security/cve/cve-2026-31431
#cve202631431 #CopyFail
Ah, the #copyfail clickbait posts are coming. Here’s my contribution. On your Linux machine add
initcall_blacklist=algif_aead_init
to your kernel boot commandline (typically in grub). Reboot. You are now safe until the updated kernel packages become available. For distributions with the grubby command this is done as root with
This mitigation comes courtesy of Red Hat. Our engineers keep you safe :)
Greg Kroah-Hartman: "If you look there are thousands of unfixed CVEs in the older LTS kernels right now, and if distros or users that rely on those older branches wish to see those resolved, they need to provide working backports to us to apply, as our first attempt did not work (which is why they are unfixed in those branches.)"
Really asking for a "Pray tell us", given that nobody actually bothered disclosing the problem to downstreams and that the commit message was hiding it.
Either way, apparently the great LLM-backed patch backporting process that #NVidia is so proud of doesn't really work. Upstream doesn't really care about #LTS branches, and they should be considered insecure by default.
https://lore.kernel.org/stable/2026050114-supernova-angler-2de1@gregkh/
#Gentoo #Linux #CopyFail #security
Replying to
@almalinux@fosstodon.org Test kernel installed on my servers and reboot done. No issue to report ! Thank you so much for your reactivity.
#copyfail #almaLinux
They: "On a scale from 1 to 10: How lazy are you?"
Me: Using the copy fail exploit instead of sudo to avoid having to type my password
#copyfail #linux #cybersecurity
Did you patch your servers against CopyFail yet? #CopyFail #CyberSecurity #Security #Linux
Note that if you the #copyfail exploit on your session, any terminal in it will be able to su without authentication (until next reboot I assume).
hotpatch:
https://lilting.ch/en/articles/linux-copy-fail-page-cache-root
Replying to
@JennyFluff@chitter.xyz You can `echo 1 > /proc/sys/vm/drop_caches` to drop the caches, after you've done something like:
$ cd /etc/modprobe.d
$ cat > af_alg.conf
blacklist af_alg
blacklist algif_aead
$
which blacklists the modules. Now, if you have legitimate use of af_alg, you can decide to only `blacklist algif_aead`, which worked to block the exploit on my Debian 13/trixie desktop running a locally-compiled 6.18.25 kernel.
Dropping the caches clears what the exploit did (changing the contents of the cached version of `/usr/bin/su`, so that cached version is always used, not the on-disk version).
#copyfail
Fresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.
It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.
https://codeberg.org/Larvitz/gists/src/branch/main/2026/20260501-CVE-2026-31431_RHEL_Mitigation.md
#Ansible #RHEL #Linux #InfoSec #SysAdmin #DevOps #CVE #CVE_2026_31431 #copyfail
Got a very silly #CopyFail container escape working.
Basically, if the container can see a file shared by the host, regardless of permissions, CopyFail can write to it on the host.
https://discourse.ifin.network/t/copy-fail-732-bytes-to-root-on-every-major-linux-distributions/342/44
Docker Engine is safe against CVE-2026-31431 now.
Patch ASAP:
https://github.com/moby/moby/releases/tag/docker-v29.4.2
#docker #containers #linux #copyfail
Fedora had released Fedora CoreOS 43.20260413.3.2 on "stable stream" few hours ago to patch against Copy Fail.
Upgraded packages:
kernel-6.19.11-200.fc43.x86_64 ⟶ 6.19.12-200.fc43.x86_64kernel-core-6.19.11-200.fc43.x86_64 ⟶ 6.19.12-200.fc43.x86_64kernel-modules-6.19.11-- 200.fc43.x86_64 ⟶ 6.19.12-200.fc43.x86_64kernel-modules-core-6.19.11-200.fc43.x86_64 ⟶ 6.19.12-200.fc43.x86_64
You can wait your zincati service schedule to upgrade automatically, or you can run sudo zincati-update-now to upgrade immediately.
#copyfail #fedora #fcos #coreos
