Severe Linux Copy Fail security flaw uncovered using AI scanning help

The Verge / 5/2/2026

📰 NewsSignals & Early TrendsIndustry & Market Moves

Key Points

  • Nearly all Linux distributions released since 2017 are affected by a severe privilege-escalation flaw known as “Copy Fail.”
  • The vulnerability, disclosed as CVE-2026-31431, lets any local user gain administrator (root) privileges.
  • Security firm Theori reports that the exploit uses a single Python script that works across vulnerable distributions without per-distro adjustments, version checks, or recompilation.
  • The article notes that “Copy Fail” is unusually dangerous because it may evade detection by common monitoring approaches, increasing the risk of silent compromise.
Devil face on a computer motherboard.

Nearly every Linux distribution released since 2017 is currently vulnerable to a security bug called "Copy Fail" that allows any user to give themselves administrator privileges. The exploit, publicly disclosed as CVE-2026-31431 on Wednesday, uses a Python script that works across all of the vulnerable Linux distributions, requiring "no per-distro offsets, no version checks, no recompilation," according to Theori, the security firm that uncovered it.

Ars Technica points out this blog post where DevOps engineer Jorijn Schrijvershof explains that what makes Copy Fail "unusually nasty" is the likelihood for it to go unnoticed by monitoring t …

Read the full story at The Verge.