CVE-2026-31431 “Copy Fail”: A 732-Byte Path to Root on Every Linux Distro Since 2017
Theori’s Copy Fail flaw turns a nine-year-old in-place optimization in the kernel’s AEAD socket layer into a deterministic 4-byte page-cache write. No race, no offset hunting, no per-distro tuning. A 732-byte Python script edits a setuid binary’s cached pages and hands you root on Ubuntu, RHEL, SUSE, and Amazon Linux without modification.