Story perspectives
Theori Releases CopyFail Exploit, Unpatched Linux Roots Exposed
5/1/2026
1 of 1
Story summary
- Theori researchers released exploit code for Linux CVE-2026-31431 (CopyFail) on Wednesday, five weeks after private disclosure.
- A 732-byte Python script writes four bytes to page cache, letting an unprivileged user gain root on Ubuntu 22.04, Debian 12 and other distributions since 2017.
- Although the kernel team patched the bug in multiple versions, many distributions remain unpatched, leaving systems vulnerable to container escapes, multi-tenant attacks and CI/CD pipeline code injection.
