SECURITY: Linux: Copy Fail (CVE-2026-31431)

Patches are well underway for a local privilege escalation (LPE) vulnerability in the Linux kernel's authencesn cryptographic template. While not a remotely accessed vulnerability, can still be accessed if remote access is compromised.1 The vulnerability affects Ubuntu, Amazon Linux, RHEL, SUSE.2

"An unprivileged local user can write four controlled bytes into the page cache of any readable file on a Linux system, and use that to gain root," the writeup from security biz Theori explains.[^1]
VERSIONS

2026v.0.1.0

REFERENCES

  1. The register's: Linux cryptographic code flaw offers fast route to root

  2. Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

Comments