April 29, 2026
Copy Fail (CVE-2026-31431): an AI-found Linux root exploit hidden since 2017
A logic bug in the kernel crypto API let a 732-byte Python script gain root on every mainstream distribution. It was surfaced by an AI code scanner in about an hour.
Copy Fail is a straight-line logic flaw in the authencesn crypto template, reachable through AF_ALG sockets and splice(), that gives an unprivileged local user a 4-byte write into the page cache. That is enough to modify a setuid binary in memory and get root, with no race and no kernel-specific offsets. Kernels built from 2017 until the fix are affected; the researchers verified Ubuntu 24.04, Amazon Linux 2023, RHEL 10.1 and SUSE 16.
The bug was found by Xint Code after about an hour of scanning the kernel crypto subsystem, reported on March 23, fixed in mainline on April 1 and disclosed on April 29, 2026. The fix reverts a 2017 in-place optimization in algif_aead; until you can patch, disabling the algif_aead module is a safe mitigation for most systems.
It became a reference example of what AI scanners can find in heavily reviewed code.
Want to see what an AI audit finds in your project? Quick scans are free and take a few minutes.
Scan a repository