INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Copy Fail Exploit Vulnerability

| 2026-05-04 21:54 CRITICAL MEDIUM
Executive Summary AI-generated
The "Copy Fail" Linux security vulnerability, dubbed CVE-2026-31431 by its discoverer Theori, has been identified as a high-severity root-privilege escalation flaw in mainstream Linux kernel builds since 2017. This AI-powered penetration testing platform, Xint, discovered the local privilege-escalation bug and reported it to the Linux kernel security team on March 23. Prior patches issued by affected distributions had already mitigated the vulnerability, but Theori's proof-of-concept exploit has now made it possible for threat actors to root Linux systems with minimal effort.
Technical Mitigations AI-generated
* Theori researchers used AI to discover and initially disclose the vulnerability, which has since been patched by major Linux distributions. * The proof-of-concept exploit was shared with the Linux kernel security team on March 23, but not publicly disclosed until April 28. * Researchers have yet to determine how many organizations have been impacted by the flaw due to its broad potential impact and lack of technical details in the initial disclosure.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-0847CVE-2022-0847 CVE-2026-31431CVE-2026-31431 CVE-2026-41651CVE-2026-41651
Target & Sectors
Global Scope
Incident Timeline
‎between 2017
Threat actors exploited a copy fail exploit available Linux vulnerability in mainstream Linux distributions built between 2017 and the patch.
infrastructure Linux
‎August 2017
Threat actors exploited a previously unknown vulnerability in the Linux operating system that was introduced as part of a source code commit made on August 2017.
‎March 23
Threat actors exploited a local privilege-escalation vulnerability in the Linux kernel.
infrastructure Linux
organisation Theori
‎April 1st
Threat actors exploited a previously unknown Linux vulnerability, CVE-2026-31431.
infrastructure Linux
vulnerability CVE-2026-31431
infrastructure 4.14
general_metric 4.14 version
‎2026/04/04
Threat actors exploited a high-severity root-privilege escalation vulnerability in Linux distros, specifically targeting the PackageKit daemon.
tactic Privilege Escalation
infrastructure Linux
vulnerability CVE-2026-41651
organisation PackageKit
‎April 29, 2026
Threat actors exploited the CVE-2026-31431 Linux vulnerability.
vulnerability CVE-2026-31431
‎2026/04/29
Threat actors used a proof-of-concept exploit to target vulnerable systems.
‎Apr 30, 2026
Threat actors exploited a known Linux vulnerability to gain unauthorized access.
‎2026/05/04
The threat actors used a Copy Fail exploit available Linux vulnerability to target major distributions including Ubuntu, RHEL, SUSE, and Amazon Linux.
infrastructure Linux
organisation Copy Fail
organisation Ubuntu 24.04
organisation Linux / Vulnerability Cybersecurity
organisation LPE
organisation Kubernetes
organisation Theori
organisation Amazon Linux 2023
infrastructure 16 devices
organisation Tharros
organisation CVE-2026-31431
organisation PoC
organisation Counter Threat Unit
organisation SophosLabs
data_breach 732 byte
organisation the Copy Fail
data_breach 4 byte
organisation CI
organisation New Linux '
organisation Copy Fail'
organisation Vulnerability Enables Root Access
organisation Amazon Linux
organisation SUSE
organisation Dirty Pipe
organisation CVE-2022-0847
infrastructure 0847 Dirty Pipe
organisation Copy Fail:
organisation CVE‑2026‑31431
infrastructure 24.04
infrastructure 10.1
infrastructure 6.12
infrastructure 6.18
organisation Ubuntu 24.04 LTS
organisation SecurityAffairs
organisation Xint.io
organisation CyberScoop
organisation AI FUD
organisation AI PoC
organisation Condon
organisation Becker
organisation BOD
organisation Sophos
organisation Next
organisation AAD
infrastructure 6.18.22
infrastructure 6.19.12
infrastructure 7.0
organisation Call execve("/usr/bin/su
organisation AEAD
organisation The Hacker News
organisation page‑cache
organisation crypto‑subsystem
organisation HMAC
organisation execve("/usr/bin/su
organisation API
‎May 12
Threat actors exploited a Linux vulnerability at the Autonomous Validation Summit on May 12.
organisation the Autonomous Validation Summit
general_metric 14 May
‎May 15
Threat actors exploited the Copy Fail security flaw to gain root shell access on four Linux distros.
infrastructure Linux
attribution CISA
attribution Copy Fail
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
16
Devices
Metrics
data_breach
732
Byte
Metrics
data_breach
4
Byte
Metrics
infrastructure
‎4.14
Software Version
Metrics
infrastructure
‎6.18.22
Software Version
Metrics
infrastructure
‎6.19.12
Software Version
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
847
Dirty Pipe
Metrics
infrastructure
‎24.04
Software Version
Metrics
infrastructure
‎10.1
Software Version
Metrics
infrastructure
‎6.12
Software Version
Metrics
infrastructure
‎6.18
Software Version