A new Linux kernel vulnerability, "Copy Fail" (CVE-2026-31431), allows local users to gain root access by writing four bytes into the page cache of readable files.
- Impact: Local Privilege Escalation (LPE) to root.
- Scope: Affects Linux kernels 4.14 and later (since 2017).
- Distributions: Impacted systems include Ubuntu, RHEL, Amazon Linux, and SUSE.
Recommended Action
Immediate patching is required. If patching is not possible, apply module-level mitigations as specified by your distribution's security advisory.