<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with copyfail]]></title><description><![CDATA[A list of topics that have been tagged with copyfail]]></description><link>https://board.circlewithadot.net/tags/copyfail</link><generator>RSS for Node</generator><lastBuildDate>Thu, 30 Apr 2026 14:19:32 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/tags/copyfail.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[@ubuntu Can you share when the updated packages to mitigate #CVE202631431 are likely to drop?]]></title><description><![CDATA[@ubuntu Can you share when the updated packages to mitigate #CVE202631431 are likely to drop? #copyfail #ubuntu #security]]></description><link>https://board.circlewithadot.net/topic/cb93a938-96e1-4d85-be54-c303cc3cc6d1/@ubuntu-can-you-share-when-the-updated-packages-to-mitigate-cve202631431-are-likely-to-drop</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/cb93a938-96e1-4d85-be54-c303cc3cc6d1/@ubuntu-can-you-share-when-the-updated-packages-to-mitigate-cve202631431-are-likely-to-drop</guid><dc:creator><![CDATA[fooflington@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Many of your systems will not have the algif_aead and af_alg kernel modules loaded prior exploiting the #copyfail vulnerability.]]></title><description><![CDATA[Many of your systems will not have the algif_aead and af_alg kernel modules loaded prior exploiting the #copyfail vulnerability. So checking your kernel logs for "NET: Registered PF_ALG protocol family" is a good #threathunting for today. #cve_2026_31431 #siem]]></description><link>https://board.circlewithadot.net/topic/906579ce-5db8-4750-9386-161878270b2c/many-of-your-systems-will-not-have-the-algif_aead-and-af_alg-kernel-modules-loaded-prior-exploiting-the-copyfail-vulnerability.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/906579ce-5db8-4750-9386-161878270b2c/many-of-your-systems-will-not-have-the-algif_aead-and-af_alg-kernel-modules-loaded-prior-exploiting-the-copyfail-vulnerability.</guid><dc:creator><![CDATA[securitym0nkey@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[I couldn&#x27;t find a list of #Linux #kernel versions that include a patch for #copyfail, so I dug into the commit log and made one.]]></title><description><![CDATA[I couldn't find a list of #Linux #kernel versions that include a patch for #copyfail, so I dug into the commit log and made one. Make sure you're using at least the following version of your branch to mitigate against copyfail:- 7.0-rc7 (any stable 7.x is safe)- 6.19.12- 6.18.22- 6.12.85- 6.6.137- 6.1.170- 5.15.204- 5.10.254See https://copy.fail for more info about the #exploit.#privilegeescalation #vulnerability #cryptography #linuxadmin #sysadmin]]></description><link>https://board.circlewithadot.net/topic/784f5fe3-6871-4e9c-bcb1-8070cdf8b9b2/i-couldn-t-find-a-list-of-linux-kernel-versions-that-include-a-patch-for-copyfail-so-i-dug-into-the-commit-log-and-made-one.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/784f5fe3-6871-4e9c-bcb1-8070cdf8b9b2/i-couldn-t-find-a-list-of-linux-kernel-versions-that-include-a-patch-for-copyfail-so-i-dug-into-the-commit-log-and-made-one.</guid><dc:creator><![CDATA[data0@indieweb.social]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Can someone explain to me why #copyfail was still unpatched on so many distros this morning when the blog post claims it was reported over a month ago to the kernel security team?]]></title><description><![CDATA[Can someone explain to me why #copyfail was still unpatched on so many distros this morning when the blog post claims it was reported over a month ago to the kernel security team?#cve_2026_31431]]></description><link>https://board.circlewithadot.net/topic/86618607-6e30-4fe5-9296-15101322c896/can-someone-explain-to-me-why-copyfail-was-still-unpatched-on-so-many-distros-this-morning-when-the-blog-post-claims-it-was-reported-over-a-month-ago-to-the-kernel-security-team</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/86618607-6e30-4fe5-9296-15101322c896/can-someone-explain-to-me-why-copyfail-was-still-unpatched-on-so-many-distros-this-morning-when-the-blog-post-claims-it-was-reported-over-a-month-ago-to-the-kernel-security-team</guid><dc:creator><![CDATA[mklovenotcyber@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[FYI: Wenn ihr das AEAD Kernel Modul als Mitigation für #CopyFail nicht entladen&#x2F;blacklisten könnt weil es builtin ist (bspw RHEL&#x2F;CentOS), könnt ihr das trotzdem per Kernel Cmdline disabeln:]]></title><description><![CDATA[FYI: Wenn ihr das AEAD Kernel Modul als Mitigation für #CopyFail nicht entladen/blacklisten könnt weil es builtin ist (bspw RHEL/CentOS), könnt ihr das trotzdem per Kernel Cmdline disabeln:"initcall_blacklist=algif_aead_init"]]></description><link>https://board.circlewithadot.net/topic/34021e58-da44-458b-a882-9a9f67179d99/fyi-wenn-ihr-das-aead-kernel-modul-als-mitigation-für-copyfail-nicht-entladen-blacklisten-könnt-weil-es-builtin-ist-bspw-rhel-centos-könnt-ihr-das-trotzdem-per-kernel-cmdline-disabeln</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/34021e58-da44-458b-a882-9a9f67179d99/fyi-wenn-ihr-das-aead-kernel-modul-als-mitigation-für-copyfail-nicht-entladen-blacklisten-könnt-weil-es-builtin-ist-bspw-rhel-centos-könnt-ihr-das-trotzdem-per-kernel-cmdline-disabeln</guid><dc:creator><![CDATA[fleaz@chaos.social]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[#copyfail is why the Forgejo Actions runner service i&#x27;m setting up will be using kvm and single shot VMs rather than containers]]></title><description><![CDATA[@whitequark awesome! Gimme some time, I'll prepare everything. How can I reach you to hand over access credentials?]]></description><link>https://board.circlewithadot.net/topic/e4b02816-3860-4318-ab8b-40a035c57c29/copyfail-is-why-the-forgejo-actions-runner-service-i-m-setting-up-will-be-using-kvm-and-single-shot-vms-rather-than-containers</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/e4b02816-3860-4318-ab8b-40a035c57c29/copyfail-is-why-the-forgejo-actions-runner-service-i-m-setting-up-will-be-using-kvm-and-single-shot-vms-rather-than-containers</guid><dc:creator><![CDATA[alex@feed.yopp.me]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Suite à une faille de sécurité élevée sur un module du noyau Linux, nous déployons actuellement des contournements sur les serveurs.]]></title><description><![CDATA[Pour information, voici les 2 tasks Ansible que l'on applique pour contourner #copyfail :https://paste.evolix.org/?e33be19335e04f0e#BDZbmCJNzevojN2fkreTUWtdPtckq8qkMzkJSgjfavJd]]></description><link>https://board.circlewithadot.net/topic/f6d72521-18c1-4f5e-8888-4b27046834e6/suite-à-une-faille-de-sécurité-élevée-sur-un-module-du-noyau-linux-nous-déployons-actuellement-des-contournements-sur-les-serveurs.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/f6d72521-18c1-4f5e-8888-4b27046834e6/suite-à-une-faille-de-sécurité-élevée-sur-un-module-du-noyau-linux-nous-déployons-actuellement-des-contournements-sur-les-serveurs.</guid><dc:creator><![CDATA[evolixnoc@piaille.fr]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Me: Nothing bad ever happened on Wednesdays.]]></title><description><![CDATA[Me: Nothing bad ever happened on Wednesdays. I should be able to relax.CopyFail:#copyfail #cve202631431]]></description><link>https://board.circlewithadot.net/topic/d04439a6-065b-4411-82fd-673982bbf62c/me-nothing-bad-ever-happened-on-wednesdays.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/d04439a6-065b-4411-82fd-673982bbf62c/me-nothing-bad-ever-happened-on-wednesdays.</guid><dc:creator><![CDATA[patlikestechnology@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Reliably detecting Copyfail https:&#x2F;&#x2F;www.threatbear.co&#x2F;blog&#x2F;detecting-copyfail-using-ebpf&#x2F; #CVE-2026-31431 #copyfail #detectionengineering]]></title><description><![CDATA[Reliably detecting Copyfail https://www.threatbear.co/blog/detecting-copyfail-using-ebpf/ #CVE-2026-31431 #copyfail #detectionengineering]]></description><link>https://board.circlewithadot.net/topic/a5e751fb-26a5-4074-8531-853c976e2a57/reliably-detecting-copyfail-https-www.threatbear.co-blog-detecting-copyfail-using-ebpf-cve-2026-31431-copyfail-detectionengineering</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/a5e751fb-26a5-4074-8531-853c976e2a57/reliably-detecting-copyfail-https-www.threatbear.co-blog-detecting-copyfail-using-ebpf-cve-2026-31431-copyfail-detectionengineering</guid><dc:creator><![CDATA[hilt@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[I deobfuscated the #copyfail exploit and fixed up the payload to run under Alpine: https:&#x2F;&#x2F;astr.al&#x2F;notes&#x2F;2026-04-29_copyfail&#x2F;]]></title><description><![CDATA[@astraleureka extremely helpful]]></description><link>https://board.circlewithadot.net/topic/c307d8be-49c3-422f-a931-d1ef782556e7/i-deobfuscated-the-copyfail-exploit-and-fixed-up-the-payload-to-run-under-alpine-https-astr.al-notes-2026-04-29_copyfail</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/c307d8be-49c3-422f-a931-d1ef782556e7/i-deobfuscated-the-copyfail-exploit-and-fixed-up-the-payload-to-run-under-alpine-https-astr.al-notes-2026-04-29_copyfail</guid><dc:creator><![CDATA[hipsterelectron@circumstances.run]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[It is nice to see getting Linux more secure every day because it is developed in the open.]]></title><description><![CDATA[@Lioh OK, so what’s your preferred vulnerability disclosure policy?Just linking the document is fine.]]></description><link>https://board.circlewithadot.net/topic/dec78193-1e12-45e9-aceb-c2be2861489d/it-is-nice-to-see-getting-linux-more-secure-every-day-because-it-is-developed-in-the-open.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/dec78193-1e12-45e9-aceb-c2be2861489d/it-is-nice-to-see-getting-linux-more-secure-every-day-because-it-is-developed-in-the-open.</guid><dc:creator><![CDATA[marshray@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[I’m a bit surprised they did not wait till a patch was available for the major distros.]]></title><description><![CDATA[I’m a bit surprised they did not wait till a patch was available for the major distros. Smells like an IPO or the next round of funding is coming soon.You probably want to keep a close eye on any system you maintain where unprivileged users have shell access and update as soon as possible.https://copy.failhttps://security-tracker.debian.org/tracker/CVE-2026-31431https://ubuntu.com/security/CVE-2026-31431https://www.suse.com/security/cve/CVE-2026-31431.html#copyfail]]></description><link>https://board.circlewithadot.net/topic/ca5167c6-bd5a-49f1-aed0-9376d633489a/i-m-a-bit-surprised-they-did-not-wait-till-a-patch-was-available-for-the-major-distros.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/ca5167c6-bd5a-49f1-aed0-9376d633489a/i-m-a-bit-surprised-they-did-not-wait-till-a-patch-was-available-for-the-major-distros.</guid><dc:creator><![CDATA[dermolly@toot.kif.rocks]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Holy. Fucking. Fuckballs.]]></title><description><![CDATA[@drwho@masto.hackers.town @thibaultmol@en.osm.town @darkrat@chaosfurs.social It is minified but really not difficult to pull apart. It opens /usr/bin/su, then repeatedly calls c(f, i, e[i:i+4]) to write the embedded payload into the cached image of /usr/bin/su in 4-byte chunks. The write-up describes this. The sendmsg() data carries the 4 controlled bytes, splice() supplies the page-cache-backed file pages, and recv() triggers the authencesn path that writes those bytes into the cached file page.After patching the cached copy, it just runs su. That's it.s.socket(38,5,0) are the numeric constants for AF_ALG and SOCK_SEQPACKET, it's equivalent to socket.socket(socket.AF_ALG, socket.SOCK_SEQPACKET, 0).The zlib blob decompresses to a 160-byte ELF executable, it basically only contains: setuid(0)
execve("/bin/sh", NULL, NULL)
exit(0)to pop a root shell.The CVE is real; I got it to work just fine on my Proxmox host (Linux 6.17.13-2)]]></description><link>https://board.circlewithadot.net/topic/62ded7b7-80de-4f06-a05f-1a905cd43949/holy.-fucking.-fuckballs.</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/62ded7b7-80de-4f06-a05f-1a905cd43949/holy.-fucking.-fuckballs.</guid><dc:creator><![CDATA[privateger@plasmatrap.com]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[What is going on today??]]></title><description><![CDATA[What is going on today??We're also tracking #CopyFail.https://discourse.ifin.network/t/copy-fail-732-bytes-to-root-on-every-major-linux-distributions/342#ThreatIntel #ThreatIntelligence #IFIN]]></description><link>https://board.circlewithadot.net/topic/b2722769-0ef9-4136-9c8b-166487d27d89/what-is-going-on-today</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/b2722769-0ef9-4136-9c8b-166487d27d89/what-is-going-on-today</guid><dc:creator><![CDATA[ifin@infosec.exchange]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Copy Fail – CVE-2026-31431]]></title><description><![CDATA[Copy Fail – CVE-2026-31431https://copy.fail/#HackerNews #CopyFail #CVE2026 #Security #Vulnerability #HackerNews #TechNews]]></description><link>https://board.circlewithadot.net/topic/89f41002-d639-4747-a05e-55c2ed7c9d65/copy-fail-cve-2026-31431</link><guid isPermaLink="true">https://board.circlewithadot.net/topic/89f41002-d639-4747-a05e-55c2ed7c9d65/copy-fail-cve-2026-31431</guid><dc:creator><![CDATA[h4ckernews@mastodon.social]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>