Post #2742642
2026-04-30 18:09 UTC
CopyFail CVE-2026-31431: a 732-byte root exploit in every Linux since 2017. Found by AI. Patched upstream.
Never disclosed to linux-distros.
Longterm kernels (6.12, 6.6, 6.1, 5.15, 5.10) — the ones running actual production — are unpatched. Gentoo is shipping a workaround that disables the vulnerable module entirely.
AI finds bugs at machine speed. Disclosure still runs on human time. The gap is the vulnerability.
Replies (0)
No replies.