The “Copy fail” Linux vulnerability (now with friends!)

FYI, allows easy root in shared kernel environments on major distros. The because Xint are complete assholes, the vulnerability was disclosed to the world as a working exploit with zero private disclosure notice to distributions to get things patched first.

Edit 2026-05-07
See part two, “dirtyfrag”, here: The “Copy fail” Linux vulnerability (now with friends!) - #32 by Log

5 Likes

Heard about that today, not affected personally but the how this was published is kinda shitty I do agree.

1 Like

It seems like grep CONFIG_CRYPTO_USER_API /boot/config-$(uname -r) is the one liner to check, does any output from this command at all suggest a system is vulnerable? :thinking:

Interesting to note (from ycombinator) that gvisor users are not affected…

Seems the real risk to me is PE from containers since this is not a remote exploit.

If you’re on Linux 7.0.0 or later, it’s already patched during RC cycles.

For other kernels, if not having “algif_aead.ko” loaded or auto-load on demand, then you aren’t vulnerable.

Blacklist the kmod also makes the system not vulnerable.

Additionally if with SELinux implemented on your system, also not vulnerable.

3 Likes

This seems like a prompt engineered vulnerability. Is it a “works on my machine” kind of a exploit, or a real verified one?

In any case, every day I ponder if corporate backed Linux is really enhancing the ecosystem. Seems like Linux was more secure three decades ago. Lower attack surface, more competent maintainers.

Instead of active iterative development, some corporation “donates” $10M to the tax fraud shell called The Linux Foundation, and both kernel plus userspace software maintainers are forced to merge garbage. Often without realizing, as they are already employed by said corporation. Been that way for more than two decades now. Not good for security.

3 Likes

It is used by iwd that seems to be the only widely installed software that uses it

A matter of opinion…

2026-03-23 Vulnerability reported to Linux kernel security team
2026-03-24 Initial acknowledgment received
2026-03-25 Patches proposed and reviewed
2026-04-01 Patches committed to mainline kernel
2026-04-22] CVE-2026-31431 assigned
2026-04-29 Public disclosure (this article)
ref: Copy Fail: 732 Bytes to Root on Every Major Linux Distribution. - Xint

Could definitely have been better outcomes for distros, though who should be on the hook for that is a bit unclear to me.

3 Likes

I figure most major distros have a team member on the kernel security team. There should probably be some way for kernel to communicate incoming security fixes to distros, otherwise we could be in for a bit of a headache.

4 Likes

Related thought:

If you want to know how secure the various ways of separating customer workloads are it’s very telling to see what Google, AWS etc do…

Gvisor, firecracker, nitro…

I don’t think they allow strangers to both share a Linux kernel and have direct access to the Linux syscall interface.

The Linux syscall interface is big and complicated and Linux has a lot of bugs, if this particular vulnerability broke your security its because you picked a high risk setup.

Still, we all should patch it asap, it helps with defence in depth.

patch your stuff. This effects the old linux kernels. if your on a rolling release your more than likely okay.

2 Likes

Yep. Didn’t even have this module enabled on most “hand-crafted” kernels. Looks like “better safe than sorry“ kind of panic, at least in many cases. No fire yet, but some smoldering in some places.

I have lots of containers, but I don’t really run anything untrusted in them, so I think I am personally safe.

That said, these Xint people are total assholes.

Not much difference between a “White” or “Grey” hat if you are just going to publicly tell all the “black” hats how to do it.

If you discover a bug and don’t give the developer a reasonable amount of time to fix it before disclosure, you should be charged with a crime, just like those who maliciously exploit these things.

I trust nothing by default :ninja:

2 Likes

They did. Linux security team was told, and we got this patch on mainline a little over a month ago:

As an aside this patch in itself is a hint that there was an exploit, it “Fixes” something, and it was reported by “theori.io” who do offensive security / vulnerability research type stuff.

What it sounds like people are wanting is exploit researchers to not only contact and work with the developers to fix the bug, but to reach beyond the developers and give the heads up to major users. They could have, but I don’t think it warrants insults or criminal charges if they don’t.

Personally if I were to find a bug in OpenSSH, I’d report it to the OpenSSH developers, and feel my obligation was done. I’d not feel I should have to reach out to Oracle, Red Hat, etc all to give them all a heads up.

Last night I was doing a search . I did find these two commands to do a check to see if there maybe anything.

first I ran

lsmod | grep algif_aead

then ran

grep -E ‘algif_aead’ /proc/crypto

I seem to be ok

hope everyone here is alright

100% The Linux Foundation is a major WEF partner and deeply aligned with the not-so-good side of the EU and UN policy frameworks (DEI, Agenda 2030 and The Fourth Industrial Revolution).

The UN merged with the WEF in 2019 under the UN-WEF Strategic Partnership Agreement. The merger was condemned by over 400 UN Civil Societies in an Open Letter to the UN Secretary General warning of global Corporatism and technocracy:

The attacks on the Libre Software philosophy in Open Source are occurring more overtly now, more frequently through destructive ideologies like ESG and DEI, lawfare, threats against individuals and projects by people deeply motivated by ideological conditioning, money, and strategic interest. In addition to legislative instruments appearing in countries all over the Western world that remove the real freedoms which allow individuals and groups to develop real solutions. Solutions that don’t serve globalist agendas. Globalist agendas that serve Corporate and Governments locked into Public Private Partnerships (Corporatism, also called Stakeholder Capitalism by the UN-WEF Strategic Partnership).

Sabotage around the world is accelerating and the globalists are increasingly brazen. Nordstream 2 was a classic sabotage event. It harmed Germany by significantly denying it access to cheap gas. That event didn’t really hurt Russia but it has collapsed numerous businesses in heavy industry reliant on abundant cheap gas, including destroying Germany’s fertiliser production. This attack on Iran by globalists through the US and Israeli coalition has stressed and weakened Germany, Europe and the entire world even more. The globalists knew that the conflict would close the Hormuz Straight (the first organisations to deny passage to the ships were the companies insuring the ships, especially Lloyds). The “Trump Administration” knew the conflict would. The generals knew it would hurt the US and allies — which it absolutely has which why many have been fired over protest and attempts to block the Trump administration from directing the military from taking actions that do incredible levels of harm. Still the coalition persists to keep the straight closed by maintaining the attacks on Iran.

Texas just had significant damage done to a very big refinery “in the middle of the biggest oil energy crisis" since oil was first discovered. Australia, India, and Romania have suffered large " events” which destroyed significant infrastructure. And now Russia — four refineries attacked by Western globalist proxies poising as Ukrainian forces. Sabotage has been occurring against oil production in the Gulf by Israeli Special Forces — Iran tells everyone exactly what they will hit before they hit it. Mossad agents were caught by Saudi forces about to blow up a second installation.

The globalists will not allow real Libre Open Source software to exist outside a global Digital ID surveillance and enforcement technocracy so all corporate distros from Red Hat, Oracle and Canonical will become fully compliant through various "excuses” to ensure safety and comply with the various legislative instruments introduced to force compliance.

Linus Torvalds is a card-carrying WEF supporter, unfortunately. He will eventually support the enforcement of compliance in the kernel.

The use of Casus Belli (justification) is an old tactic and sabotage is another instrument to justify planned, strategic responses.

Interestingly the globalists (including the Epstein Class) are using the Epstein Files as Casus Belli to roll out Age Verification — which is a strategic precursor to a Digital ID surveillance and enforcement ”governance“ framework that will be rapidly combined with a realtime Zero Trust infrastructure (including realtime application of policy frameworks via Smart Contract blockchain payment infrastructure aka Social Credit systems).

So yeah — exploits, hacks, persecution and QA failures across traditionally robust and stable codebases will increase to whatever is required to bring Libre Software into compliance with global technocratic policy frameworks.

3 Likes

@nickwalt Yeah that’s certainly a way to hijack and ridicule my point, thanks for that I guess you absolute troll.

1 Like

pointing-tin-hat-6a2zrfos0bh76dem-3847561237

5 Likes

Some tech bros are asleep — ok, maybe more than just a few. Thankfully some take their tinfoil hats off and observe the world around them because tinfoil hats are for the ignorant — those who ignore that which is right in front of their faces. Clearly the WEF is a huge problem as disclosed in the Open Letter from the over 400 UN Civil Societies — those are orgs, not just individuals.

BlackRock CEO, Larry Fink, certainly believes in the WEF, its mission and agendas — so much he became chairman. So does Peter Thiel, Alex Karp, Larry Ellison, Sam Altman and (especially) Bill Gates.

We may not believe in the WEF but the WEF believes in us — Larry Fink speech about embracing the world:

Trolling? You guys clearly don’t watch Steve from Gamers Nexus talk about the Corporatism and the WEF. The globalists and the Epstein Class. Same with Wendel though Wendel is more low-key.

Is Copy Fail an act of sabotage? It was disclosed on a manner that gave very few individuals and orgs time to respond and hurt many. The exploit itself might not be sabotage but someone found it and told the world in a careless and almost negligent act of disclosure.

I watched Wendel’s podcast about it and he was seriously concerned.

You guys can continue to put your heads in the sand if you like but the reality is that a global technocracy will not tolerate free and independent non-compliant Open Source software.

Here’s a little gem from Agustin Carstens who was head of the BIS in 2020. He talks about programmable currency aka CBDC and Stablecoins:

Good luck with the foil hat thing.

1 Like

Okay

1 Like