Linux Kernel Flaw "Copy Fail" PoC Public
A local privilege-escalation vulnerability in the Linux kernel, dubbed Copy Fail (CVE-2026-31431), has public exploit code available, IPA warns.
Japan's IPA has issued an alert on CVE-2026-31431, nicknamed "Copy Fail," a privilege-escalation vulnerability affecting the Linux kernel from version 4.14 onward. The flaw requires local, low-privileged access (CVSS vector AV:L, PR:L) and is not remotely exploitable, but a successful exploit allows an already-authenticated local user to escalate to administrator/root privileges.
IPA notes that proof-of-concept exploit code for the vulnerability is already publicly available, raising the risk of exploitation, particularly when chained with other vulnerabilities or in multi-tenant environments such as shared containerized systems where multiple users share a kernel. The advisory does not indicate evidence of active in-the-wild exploitation but flags the public PoC as a significant risk factor.
IPA advises organizations to monitor distribution-specific advisories for patch availability and apply updates promptly. Where patches are not yet available, vendors may offer workarounds, though IPA cautions that these should be thoroughly tested before deployment due to potential operational impact.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260501.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free