The most severe Linux threat to surface in years catches the world flat-footed
CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more.
Signal weather
Stable
The story has moved beyond the first headline and now acts as a reliable context anchor.
Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices. The vulnerability and exploit code that exploits it were released Wednesday evening by researchers from security firm Theori, five weeks after privately disclosing it to the Linux kernel security team. The team patched the vulnerability in versions 7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254) but few of the Linux distributions had incorporated those fixes at the time the exploit was released. A single script hacks all distros The critical flaw, tracked as CVE-2026-31431 and the name CopyFail, is a local privilege escalation, a vulnerability class that allows unprivileged users to elevate themselves to administrators. CopyFail is particularly severe because it can be exploited with a single piece of exploit code—released in Wednesday’s disclosure—that works across all vulnerable distributions with no modification. With that, an attacker can, among other things, hack multi-tenant systems, break out of containers based on Kubernetes or other frameworks, and create malicious pull requests that pipe the exploit code through CI/CD work flows. Read full article Comments
Stay on the signal
Follow The most severe Linux threat to surface in years catches the world flat-footed
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Entity pages
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
3
Related articles
More stories that share tags, source, or category context.
Арендовал виртуалку – получил root на хосте. Уязвимость в ядре Linux, которую два года никто не замечал
Уязвимость ITScape позволяла виртуальной машине переписывать правила на физическом сервере.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Did a medieval flying monk spot Halley's comet, twice? It's complicated
University of Leicester historian thinks Eilmer of Malmesbury saw two different comets: in 1018 and 1066
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Linux 7.1
Comments
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
В Arch Linux нашли вредонос-матрёшку: пакет внутри пакета, а на самом дне — похититель паролей
400 пакетов, одна старая лазейка — и доступ ко всему: от браузера до криптокошельков.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Did a medieval flying monk spot Halley's comet, twice? It's complicated
University of Leicester historian thinks Eilmer of Malmesbury saw two different comets: in 1018 and 1066
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Review: Disclosure Day is big on action, light on ideas
There's nothing new or surprising, but it's still an entertaining film from one of our greatest directors.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Threads of underground fungal networks are long enough to reach beyond the Solar System
Researchers have quantified the length and mass of arbuscular mycorrhizal fungal networks globally.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Anthropic shuts down Fable, Mythos models following Trump admin directive
Commerce dept. worries that a Fable 5 "jailbreak" could be a national security threat.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.