1 link tagged with all of: linux + security + kernel + privilege-escalation
Click any tag below to further narrow down your results
Links
Cloudflare’s teams quickly reviewed CVE-2026-31431 (“Copy Fail”), confirmed their behavioral detections flagged the exploit within minutes, and found no signs of in-the-wild abuse. They ran fleet-wide threat hunts, deployed a bpf-lsm mitigation, and rolled out updated kernels without impacting services or customer data.
- Cloudflare's anomaly-based behavioral detection caught the "Copy Fail" exploit pattern within minutes, without a CVE-specific rule ever being written.
- A 48-hour log hunt turned up no evidence of pre-disclosure exploitation in the wild.
- Cloudflare patched its fleet across 330 cities with zero downtime or customer data exposure, using weekly kernel builds and rolling reboots.
- The bug itself let an unprivileged process abuse the AF_ALG crypto interface to corrupt cached files (e.g., /usr/bin/su) for root privilege escalation.