Forgot your password?
typodupeerror
Security Microsoft Windows Linux

Microsoft Issues Warning About Linux 'Copy Fail' Vulnerability (linux-magazine.com) 27

joshuark shares a report from Linux Magazine: Microsoft has issued a warning that a vulnerability with a CVSS score of 7.8 has been found in the Linux kernel. The vulnerability in question is tagged CVE-2026-31431 and, according to the Cybersecurity and Infrastructure Security Agency (CISA), "This Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."

The distributions affected are Ubuntu, Red Hat, SUSE, Debian, Fedora, Arch Linux, and Amazon Linux. This could also affect any distribution based on those in the list, which means pretty much every Linux distro that isn't independent. The flaw is found in the Linux kernel cryptographic subsystem's algif_aead module of AF_ALG. The problem is that a particular optimization has led to the kernel reusing the source memory as the destination during cryptographic operations. What this means is that attackers can take advantage of interactions between the AF_ALG socket interface and a splice() system call. Until patches are released, Microsoft is advising that the affected crypto feature should be disabled, or AF_ALG socket creation should be blocked.
The vulnerability is also known as "Copy Fail," which has been shared on Slashdot and detailed in a technical report. The vulnerability affects almost every version of the Linux OS and is now being exploited in the wild. U.S. cybersecurity agency CISA has ordered all civilian federal agencies to patch any affected systems by May 15.

Microsoft Issues Warning About Linux 'Copy Fail' Vulnerability

Comments Filter:
  • by CAIMLAS ( 41445 ) on Thursday May 07, 2026 @04:19PM (#66132888)

    This is literally the third /. mention of this in a very short period of time, nevermind the fact that it's been broadcast literally everywhere and is the biggest security vuln found since sliced bread (or heartbleed). It's been fixed and available for "ages" now on every major distro.

    • This is literally the third /. mention of this in a very short period of time, nevermind the fact that it's been broadcast literally everywhere and is the biggest security vuln found since sliced bread (or heartbleed). It's been fixed and available for "ages" now on every major distro.

      One would almost begin to suspect that there is a vested interest in making Linux appear to be far more vulnerable than the "alternatives" to Linux.

    • by HiThere ( 15173 )

      Not for ages. Less than a week. For many, that's not time enough to get the patch.

      OTOH, it's a local vulnerability, so many systems aren't affected. I've got one that hasn't been hooked up to the internet in well over a month, and it won't be affected until the next time it's hooked up. (I may do a reinstall before then.)

    • Also, why the fuck is it news that Microsoft is posting about it? TFS or TFA give absolutely no indication as to why.

      This is just a dupe, nothing more.

      • Also, why the fuck is it news that Microsoft is posting about it? TFS or TFA give absolutely no indication as to why.

        This is just a dupe, nothing more.

        Because M$ is THE EXPERT on vulnerabilities.

    • by znrt ( 2424692 )

      our apologies, sir. would you prefer a slashvertisement instead?

    • Not really ages, a week. mind you the article they are talking about is a week old and related to Microsoft Defender which is used by customers to monitor cloud servers, many of which are unsuprisingly linux. So while this slashdot article seems to try and imply it is MS pointing fingers, it is nothing of the sort. It is just a standard blog article warning its userbase of an at the time very serious vulnerability, why it is here a week later on slashdot is another question.
  • How dare you dump Microslop for Linux....
  • by dskoll ( 99328 ) on Thursday May 07, 2026 @04:43PM (#66132928) Homepage

    Old news and 3 times on Slashdot. The new kids have already moved on to Dirty Frag [github.com], a new Linux local privilege escalation vulnerability.

    • The new kids have already moved on to Dirty Frag [github.com], a new Linux local privilege escalation vulnerability.

      Question is, who's the jackass that broke the embargo on this one?

  • Not news (Score:5, Informative)

    by Himmy32 ( 650060 ) on Thursday May 07, 2026 @04:53PM (#66132944)

    The article doesn't even link to the Microsoft article [microsoft.com], which is on the Microsoft Defender blog. This isn't a huge surprise since that's Microsoft's security product that covers cloud servers including in Azure, AWS and GCP [microsoft.com].

    So the sub-text of this being Microsoft pointing out Linux vulns is pretty silly since Microsoft makes a lot of money off of people running Linux on their cloud and on their competitors' kit. Outside of that, the rest of this has already been covered.

  • https://dirtyfrag.io. Nearly the same vulnerability, different access vector.

The best things in life go on sale sooner or later.

Working...