Severe Linux Copy Fail security flaw uncovered using AI scanning help

Devil face on a computer motherboard.

Nearly every Linux distribution released since 2017 is currently vulnerable to a security bug called “Copy Fail” that allows any user to give themselves administrator privileges. The exploit, publicly disclosed as CVE-2026-31431 on Wednesday, uses a Python script that works across all of the vulnerable Linux distributions, requiring “no per-distro offsets, no version checks, no recompilation,” according to Theori, the security firm that uncovered it.

Ars Technica points out this blog post where DevOps engineer Jorijn Schrijvershof explains that what makes Copy Fail “unusually nasty” is the likelihood for it to go unnoticed by monitoring t …

Read the full story at The Verge.

Read more @ TheVerge

Latest posts

How to Build a RAG-Based AI System Step-by-Step?

The use of Artificial Intelligence (AI) to provide reliable and contextually aware answers is increasingly the norm amongst businesses, yet the conventional models of...

Leaked images reveal Xbox Elite 3 controller with mysterious new buttons

Hours after a smaller Xbox Cloud Gaming controller appeared online, Brazil's Anatel regulator has also accidentally published images of what appears to be Microsoft's...

Behold, the Elon Musk jackass trophy

Yesterday, in Musk v. Altman, before the jurors came in, Sam Altman's team passed up what looked - from a distance - like a...

Meta brings virtual writing to everyone with Meta Ray-Ban Display glasses

Meta is rolling out new features to its Meta Ray-Ban Display smart glasses, including bringing the ability to write messages just with hand gestures...

Metroid Prime 4: Beyond got its first big discount

The most graphically-impressive first-person shooter made for the Nintendo Switch is $20 off at Best Buy. Right now, you can buy the physical version...

Closing time

Today was closing arguments in the Musk v. Altman trial, and I almost feel bad writing about the unbelievable demolition derby I just witnessed....

Honda’s hybrid future starts with new Accord and RDX prototypes

Honda revealed prototypes of two new hybrid models, an Accord sedan and the Acura RDX SUV, during its annual business briefing this week, built...

Google Phone, system dialers can show calls from third-party apps

Google is giving developers of third-party calling apps the ability to integrate with Phone by Google and other system dialers. Read more @ 9to5google

Subnautica 2 is having a huge launch on Steam

Subnautica 2, the new underwater survival game from Unknown Worlds, took less than an hour to rocket up Steam's charts. The game has already...

Use this map to find the data centers in your backyard

An interactive map tracking data center construction and AI policy, built by Isabelle Reksopuro. When Oregon resident Isabelle Reksopuro heard Google was gobbling up public...