‼️🚨 BREAKING: An AI found a Linux kernel zero-day that roots every distribution since 2017. The exploit fits in 732 bytes of Python. Patch your kernel ASAP.
The vulnerability is CVE-2026-31431, nicknamed "Copy Fail," disclosed today by Theori. It has been sitting quietly in the Linux kernel for nine years.
Most Linux privilege-escalation bugs are picky. They need a precise timing window (a "race"), or specific kernel addresses leaked from somewhere, or careful tuning per distribution. Copy Fail needs none of that. It is a straight-line logic mistake that works on the first try, every time, on every mainstream Linux box.
The attacker just needs a normal user account on the machine. From there, the script asks the kernel to do some encryption work, abuses how that work is wired up, and ends up writing 4 bytes into a memory area called the "page cache" (Linux's high-speed copy of files in RAM). Those 4 bytes can be aimed at any program the system trusts, like /usr/bin/su, the shortcut to becoming root.
Result: the next time anyone runs that program, it lets the attacker in as root.
What should worry most: the corruption never touches the file on disk. It only exists in Linux's in-memory copy of that file. If you imaged the hard drive afterwards, the on-disk file would match the official package hash exactly. Reboot the machine, or just put it under memory pressure (any normal system load that needs the RAM), and the cached copy reloads fresh from disk.
Containers do not help either. The page cache is shared across the whole host, so a process inside a container can use this bug to compromise the underlying server and reach into other tenants.
The original sin was a 2017 "in-place optimization" in a kernel crypto module called algif_aead. It was meant to make encryption slightly faster. The change broke a critical safety assumption, and nobody noticed for nine years. That bug then rode every kernel update from 2017 to today.
This vulnerability affects the following:
🔴 Shared servers (dev boxes, jump hosts, build servers): any user becomes root
🔴 Kubernetes and container clusters: one compromised pod escapes to the host
🔴 CI runners (GitHub Actions, GitLab, Jenkins): a malicious pull request becomes root on the runner
🔴 Cloud platforms running user code (notebooks, agent sandboxes, serverless functions): a tenant becomes host root
Timeline:
🔴 March 23, 2026: reported to the Linux kernel security team
🔴 April 1: patch committed to mainline (commit a664bf3d603d)
🔴 April 22: CVE assigned
🔴 April 29: public disclosure
Mitigation: update your kernel to a build that includes mainline commit a664bf3d603d. If you cannot patch immediately, turn off the vulnerable module:
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
rmmod algif_aead 2>/dev/null || true
For environments that run untrusted code (containers, sandboxes, CI runners), block access to the kernel's AF_ALG crypto interface entirely, even after patching. Almost nothing legitimate needs it, and blocking it shuts the door on this whole class of bug...
🚨GRAVÍSIMO: DARIO MONTEROS MINISTRO DE JALDO FIRMÓ DECRETO CON FECHA DE 1 DE MARZO DEL DESPIDO DEL AGRESOR DE PELLI PARA QUE AL MOMENTO DEL INCIDENTE NO SEA EMPLEADO DEL GOBIERNO.
🚨ATENCIÓN, NO LO DETUVIERON 🚨
SEGÚN SE MUESTRA EN EL VIDEO QUE SUBIERON LOS MEDIOS, EL AGRESOR DE @pellifederico NO FUE ESPOSADO NI DETENIDO POR LA POLICÍA DE LA PROVINCIA DE TUCUMÁN.
QUE ESTE ESCÁNDALO SEA CONOCIDO A NIVEL NACIONAL!!!
#Tucumán
Ya #SomosFormosa
Sí, el señor de remera negra, anteojos y gorra es nuestro Ministro del Interior en Tucumán. Su esposa es diputada nacional, su hijo es intendente de Banda del Río Salí. Seguro te suena ese nombre: hace un año saltó que allí se “extraviaron” 17.000.000.000 de pesos. No, no me confundí con los ceros: diecisiete mil millones.
Iba a darte más detalles pero el video lo presenta mejor que cualquier currículum. Se llama Darío Monteros.
@dmitriybabenkoo Why not USDT? It looks shady. It doesn’t seem that USDT has more exposure to deUSD than USDC/USDS, so why are USDT holders being punished?
No joke: 🇶🇦 Qatar was just elected to the U.N. Women's Rights Commission.
Under the regime's misogynistic laws, Qatari women wishing to attend the next U.N. women's rights summit will need to first seek permission from their male guardians.
The inmates are running the asylum.
🇺🇸 SILK ROAD FOUNDER HOPES TRUMP WILL FREE HIM AS PROMISED
Ross Ulbricht is currently serving a life sentence in federal prison after being convicted in 2015 for creating the Silk Road marketplace.
Ulbricht:
"After 11+ years in darkness, I can finally see the light of freedom at the end of the tunnel."
Trump had previously vowed at a Libertarian event to secure Ulbricht’s release “on day one” if elected.
Source: Cointelegraph
I'm doing a podcast with Javier Milei (@JMilei) soon. 2+ hour conversation, in Spanish 😎
We'll subtitle & overdub it in English, so you can listen in either English or Spanish.
Let me know if you have questions/topic suggestions.