Mark RadarMARK RADAR
EN
Event File AI AI Cybersecurity

High-Risk Linux Flaw Copy Fail Discovered With Help From AI Tool

5 reports · First detected 2026-05-01 · Last active 2026-05-06

Cybersecurity firm Theori has disclosed a high-risk Linux kernel vulnerability designated CVE-2026-31431 and named Copy Fail. The flaw went undetected for nine years and allows local users to escalate their privileges to root. Its potential impact is significant because Linux is widely used by Ubuntu, Red Hat Enterprise Linux (RHEL), and cloud and container infrastructure.

In 2026, Theori used its AI security tool Xint Code to audit the kernel code and discover Copy Fail within one hour. Subsequent research found that the flaw could bypass Kubernetes protections, while Microsoft warned that attackers could use it to compromise cloud environments. The U.S. government also said the vulnerability had been actively exploited and urged affected organizations to patch it immediately.

All Coverage

5 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR