CVE-2026-31431
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-05-01, due 2026-05-15
- Exploitation
- No report
- Public exploits
- 319 repositories
- State
- Unknown
Coverage
Actively exploitedCERT-EU
2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")(opens the publisher's site in a new tab)
On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has…

Actively exploitedWiz Research
Copy Fail: Universal Linux Local Privilege Escalation Vulnerability(opens the publisher's site in a new tab)
Detect and mitigate Copy Fail (CVE-2026-31431), an easily exploitable vulnerability in the Linux kernel that allows escalation from an unprivileged local user account to root access.
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev