Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
The most severe Linux threat to surface in years catches the world flat-footed

The most severe Linux threat to surface in years catches the world flat-footed

Posted on May 1, 2026 By safdargal12 No Comments on The most severe Linux threat to surface in years catches the world flat-footed
Blog

Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices.

The vulnerability and exploit code that exploits it were released Wednesday evening by researchers from security firm Theori, five weeks after privately disclosing it to the Linux kernel security team. The team patched the vulnerability in versions 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254) but few of the Linux distributions had incorporated those fixes at the time the exploit was released.

A single script hacks all distros

The critical flaw, tracked as CVE-2026-31431 and the name CopyFail, is a local privilege escalation, a vulnerability class that allows unprivileged users to elevate themselves to administrators. CopyFail is particularly severe because it can be exploited with a single piece of exploit code—released in Wednesday’s disclosure—that works across all vulnerable distributions with no modification. With that, an attacker can, among other things, hack multi-tenant systems, break out of containers based on Kubernetes or other frameworks, and create malicious pull requests that pipe the exploit code through CI/CD work flows.

“‘Local privilege escalation’ sounds dry, so let me unpack it,” researcher Jorijn Schrijvershof wrote Thursday. “It means: an attacker who already has some way to run code on the machine, even as the most boring unprivileged user, can promote themselves to root. From there they can read every file, install backdoors, watch every process, and pivot to other systems.”

Schrijvershof added that the same Python script Theori released works reliably for Ubuntu 22.04, Amazon Linux 2023, SUSE 15.6, and Debian 12. The researcher continued:



Source link

Post Views: 2

Post navigation

❮ Previous Post: After dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, too
Next Post: Best Tablets in 2026: Top Picks from Apple, Samsung and Amazon ❯

You may also like

Google Rolls Out New Travel Features, Just in Time for Summer
Blog
Google Rolls Out New Travel Features, Just in Time for Summer
April 21, 2026
Marathon battery life makes Keychron’s Ultra 8K keyboards its best yet
Blog
Marathon battery life makes Keychron’s Ultra 8K keyboards its best yet
April 20, 2026
The most ridiculous tech ‘problems’ I’ve ever been asked to fix
Blog
The most ridiculous tech ‘problems’ I’ve ever been asked to fix
April 10, 2026
Huawei Pura 90 is also official with triple camera, 6,500mAh battery
Blog
Huawei Pura 90 is also official with triple camera, 6,500mAh battery
April 21, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • People are finally using Reddit’s search
  • Survey reveals how Pixel fans feel about Tensor G5’s lackluster gaming power
  • New Releases on Netflix in May: MMA, and Shows from The Duffer Brothers, Tina Fey and More
  • A 240Hz display? The latest OnePlus 16 leak reeks of desperation
  • Peacock: 14 of the Best Movies to Stream Right Now

Recent Comments

No comments to show.

Archives

  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown