Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

RCMP respond to shots fired in Behchokǫ̀, residents told to shelter in place

May 1, 2026

Carney: Canada won’t leverage energy, critical minerals in U.S. trade talks

May 1, 2026

Imperial Oil churning out more diesel, jet fuel as Mideast war drives up prices

May 1, 2026

Kylie Jenner sued by 2nd ex-housekeeper alleging workplace discrimination

May 1, 2026

Amazon’s built-in AI price history expands to show the entire last year

May 1, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » Severe Linux Copy Fail security flaw uncovered using AI scanning help
Technology

Severe Linux Copy Fail security flaw uncovered using AI scanning help

By News RoomMay 1, 20262 Mins Read
Severe Linux Copy Fail security flaw uncovered using AI scanning help
Share
Facebook Twitter LinkedIn Pinterest Email

Nearly every Linux distribution released since 2017 is currently vulnerable to a security bug called “Copy Fail” that allows any user to give themselves administrator privileges. The exploit, publicly disclosed as CVE-2026-31431 on Wednesday, uses a Python script that works across all of the vulnerable Linux distributions, requiring “no per-distro offsets, no version checks, no recompilation,” according to Theori, the security firm that uncovered it.

Ars Technica points out this blog post where DevOps engineer Jorijn Schrijvershof explains that what makes Copy Fail “unusually nasty” is the likelihood for it to go unnoticed by monitoring tools: “Page-cache corruption never marks the page dirty. The kernel’s writeback machinery never flushes the modified bytes back to disk.” As a result, “AIDE, Tripwire, OSSEC and any monitoring tool that compares on-disk checksums see nothing.”

Copy Fail was identified by Theori’s researchers with assistance from their Xint Code AI tool. According to a blog post, Taeyang Lee had an idea of looking into the crypto subsystem of Linux and created this prompt to run an automated scan that identified several vulnerabilities in “about an hour.”

“This is the linux crypto/ subsystem. Please examine all codepaths reachable from userspace syscalls. Note one key observation: splice() can deliver page-cache references of read-only files (including setuid binaries) to crypto TX scatterlists.”

According to the exploit’s disclosure page, a patch for Copy Fail was added to the mainline Linux kernel on April 1st. However, as Ars Technica notes, the researchers who identified Copy Fail published the details of the exploit publicly before all of the affected distributions could release patches for it. Some distros, including Arch Linux, RedHat Fedora, and Amazon Linux, have released patches, but many others were not immediately able to address the issue.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Amazon’s built-in AI price history expands to show the entire last year

Birdfy’s smart bird feeder is down to its best-ever price for Mother’s Day

We just got a new reason to believe the Trump phone is real(ish)

Aurzen’s teeny tiny tri-fold projector is on sale for 40 percent off

Some of Xteink’s credit card-sized e-readers are losing their best feature

Oura adds birth control support to its period tracker

Dyson put someone else’s motor in its robot vacuum

Microsoft wants lawyers to trust its new AI agent in Word documents

Meta threatens to pull its apps from New Mexico if forced to make ‘technologically impractical’ changes

Editors Picks

Carney: Canada won’t leverage energy, critical minerals in U.S. trade talks

May 1, 2026

Imperial Oil churning out more diesel, jet fuel as Mideast war drives up prices

May 1, 2026

Kylie Jenner sued by 2nd ex-housekeeper alleging workplace discrimination

May 1, 2026

Amazon’s built-in AI price history expands to show the entire last year

May 1, 2026

Latest News

GuardHouse Camera Analyzed: All You Need To Know About the GuardHouse Watch Eye

May 1, 2026

Shippers ‘losing faith’ in CBSA tech systems amid ongoing outages, glitches

May 1, 2026

Neither Norway nor Singapore: Decoding Canada’s new sovereign wealth fund

May 1, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version