Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    With help from data, art museums are reframing the visitor experience

    July 25, 2026

    Trump faces AI backlash from unions and data-center critics: Analysis

    July 25, 2026

    Samsung Elec wins $200 billion Broadcom AI chip partnership, boosting foundry push

    July 25, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»The most severe Linux threat to surface in years catches the world flat-footed
    Tech

    The most severe Linux threat to surface in years catches the world flat-footed

    franperez66q@protonmail.comBy franperez66q@protonmail.comMay 1, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices.

    The vulnerability and exploit code that exploits it were released Wednesday evening by researchers from security firm Theori, five weeks after privately disclosing it to the Linux kernel security team. The team patched the vulnerability in versions 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254) but few of the Linux distributions had incorporated those fixes at the time the exploit was released.

    A single script hacks all distros

    The critical flaw, tracked as CVE-2026-31431 and the name CopyFail, is a local privilege escalation, a vulnerability class that allows unprivileged users to elevate themselves to administrators. CopyFail is particularly severe because it can be exploited with a single piece of exploit code—released in Wednesday’s disclosure—that works across all vulnerable distributions with no modification. With that, an attacker can, among other things, hack multi-tenant systems, break out of containers based on Kubernetes or other frameworks, and create malicious pull requests that pipe the exploit code through CI/CD work flows.

    “‘Local privilege escalation’ sounds dry, so let me unpack it,” researcher Jorijn Schrijvershof wrote Thursday. “It means: an attacker who already has some way to run code on the machine, even as the most boring unprivileged user, can promote themselves to root. From there they can read every file, install backdoors, watch every process, and pivot to other systems.”

    Schrijvershof added that the same Python script Theori released works reliably for Ubuntu 22.04, Amazon Linux 2023, SUSE 15.6, and Debian 12. The researcher continued:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    With help from data, art museums are reframing the visitor experience

    July 25, 2026

    From Silicon Valley to DC, tech world obsessed with AI distillation

    July 25, 2026

    Team uses AlphaFold AI to redesign gene-editing proteins to make them safer

    July 25, 2026

    Anthropic’s Claude Opus 5 AI model rivals Fable 5 and is cheaper

    July 25, 2026

    European Union grants US request to restrict satellite images of Iran War region

    July 25, 2026

    Nvidia locks down memory from SK Hynix as part of $500 billion AI deal

    July 25, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    With help from data, art museums are reframing the visitor experience

    July 25, 2026

    Trump faces AI backlash from unions and data-center critics: Analysis

    July 25, 2026

    Samsung Elec wins $200 billion Broadcom AI chip partnership, boosting foundry push

    July 25, 2026

    From Silicon Valley to DC, tech world obsessed with AI distillation

    July 25, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.