U.S. cybersecurity agency warns of actively exploited Linux ‘CopyFail’ vulnerability
The U.S. government warns of an actively exploited Linux vulnerability, "CopyFail," impacting major distributions and posing a risk to data centers.
Jason Kwon ·

The U.S. government’s cybersecurity agency, CISA, issued an alert on May 4, 2026 warning of an actively exploited security flaw affecting major versions of the Linux operating system.
The vulnerability, tracked as CVE-2026-31431 and dubbed “CopyFail,” was found in Linux kernel versions 7.0 and earlier. The bug can allow an attacker to take complete control of a vulnerable system, raising the risk for servers and data centers that rely on Linux.
The Linux kernel security team patched the issue in late March 2026, but the fix has not yet been fully integrated across many Linux distributions, leaving some systems exposed.
Security firm Theori identified the vulnerability and said it affects widely used environments including Red Hat Enterprise Linux 10.1, Ubuntu 24.04 (LTS), Amazon Linux 2023, and SUSE 16. The exploit also affects Debian, Fedora, and some Kubernetes environments.
CISA urged organizations to apply available patches and mitigations as soon as possible.