Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
The most severe Linux threat to surface in years catches the world flat-footed

The most severe Linux threat to surface in years catches the world flat-footed

Posted on May 1, 2026 By safdargal12 No Comments on The most severe Linux threat to surface in years catches the world flat-footed
Blog

Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices.

The vulnerability and exploit code that exploits it were released Wednesday evening by researchers from security firm Theori, five weeks after privately disclosing it to the Linux kernel security team. The team patched the vulnerability in versions 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254) but few of the Linux distributions had incorporated those fixes at the time the exploit was released.

A single script hacks all distros

The critical flaw, tracked as CVE-2026-31431 and the name CopyFail, is a local privilege escalation, a vulnerability class that allows unprivileged users to elevate themselves to administrators. CopyFail is particularly severe because it can be exploited with a single piece of exploit code—released in Wednesday’s disclosure—that works across all vulnerable distributions with no modification. With that, an attacker can, among other things, hack multi-tenant systems, break out of containers based on Kubernetes or other frameworks, and create malicious pull requests that pipe the exploit code through CI/CD work flows.

“‘Local privilege escalation’ sounds dry, so let me unpack it,” researcher Jorijn Schrijvershof wrote Thursday. “It means: an attacker who already has some way to run code on the machine, even as the most boring unprivileged user, can promote themselves to root. From there they can read every file, install backdoors, watch every process, and pivot to other systems.”

Schrijvershof added that the same Python script Theori released works reliably for Ubuntu 22.04, Amazon Linux 2023, SUSE 15.6, and Debian 12. The researcher continued:



Source link

Post Views: 1

Post navigation

❮ Previous Post: After dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, too
Next Post: Best Tablets in 2026: Top Picks from Apple, Samsung and Amazon ❯

You may also like

iPhone with 200MP telephoto camera may not arrive until 2028
Blog
iPhone with 200MP telephoto camera may not arrive until 2028
April 23, 2026
How to manage multiple android devices remotely with MDM
Blog
How to manage multiple android devices remotely with MDM
April 14, 2026
GitHub – refactoringhq/tolaria · GitHub
Blog
GitHub – refactoringhq/tolaria · GitHub
April 24, 2026
Honor 600 and 600 Pro arrive with 200MP cameras, IP69K ratings and bold new designs
Blog
Honor 600 and 600 Pro arrive with 200MP cameras, IP69K ratings and bold new designs
April 23, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • A 240Hz display? The latest OnePlus 16 leak reeks of desperation
  • Peacock: 14 of the Best Movies to Stream Right Now
  • The vivo X300 FE launches in Europe, including the special edition with a Zeiss Tele Extender Lens
  • Retro gamers have a new way to play Commodore 64 and Spectrum games
  • Best Tablets in 2026: Top Picks from Apple, Samsung and Amazon

Recent Comments

No comments to show.

Archives

  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown