Connect with us

News

US government warns of severe CopyFail bug affecting major versions of Linux

info

Published

on

Lukas NLSXFjl nhc unsplash.jpg

A severe security vulnerability affecting almost every version of the Linux operating system has caught defenders off-guard and scrambling to patch after security researchers publicly released exploit code that allows attackers to take complete control of vulnerable systems.

The U.S. government says the bug, dubbed “CopyFail,” is now being exploited in the wild, meaning it’s being actively used in malicious hacking campaigns.

The bug, officially tracked as CVE-2026-31431 and discovered in Linux kernel versions 7.0 and earlier, was disclosed to the Linux kernel security team in late March, and patched after about a week. But the patches have yet to fully trickle down to the many Linux distributions that rely on the vulnerable kernel, leaving any system running an affected Linux version at risk of compromise.

Linux is widely used in enterprise settings, running the computers that operate much of the world’s datacenters. 

The CopyFail website says that the same short Python script “roots every Linux distribution shipped since 2017.”  According to security firm Theori, which discovered CopyFail, the vulnerability was verified in several widely used versions of Linux including Red Hat Enterprise Linux 10.1, Ubuntu 24.04 (LTS), Amazon Linux 2023, as well as SUSE 16. 

Devops engineer and developer Jorijn Schrijvershof wrote in a blog post that the exploit works on Debian and Fedora versions, as well as Kubernetes, which relies on the Linux kernel. Schrijvershof described the bug as having an “unusually big blast radius” as it works on “nearly every modern distribution” of Linux.

The bug is called CopyFail because the affected component in the Linux kernel, the core of the operating system that has virtually complete access to the entire device, does not copy certain data when it should. This corrupts sensitive data within the kernel, allowing the attacker to piggyback the kernel’s access to the rest of the system, including its data.

If exploited, the bug is particularly problematic because it allows a regular, limited-access user to gain full-administrator access on an affected Linux system. A successful compromise of a server in a datacenter could allow an attacker to gain access to every application, server, and database of numerous corporate customers, and potentially gain access to other systems on the same network or datacenter.

The CopyFail bug cannot be exploited over the internet on its own, but can be weaponized if used in conjunction with an exploit that works over the internet. Per Microsoft, if the CopyFail bug is chained together with another vulnerability that can be delivered over the internet, an attacker could use the flaw to gain root access to an affected server. A user operating a Linux computer with a vulnerable kernel could also be tricked into opening a malicious link or attachment that triggers the vulnerability.

The bug could also be injected by way of supply chain attacks, in which malicious actors hack into an open source developer’s account and plant the malware in their code in order to compromise a large number of devices in one go.

Given the risk to the federal enterprise network, U.S. cybersecurity agency CISA has ordered all civilian federal agencies to patch any affected systems by May 15.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Party Deregistration: ADC youth wing petitions NJC, demands Lifu’s removal

info

Published

on

By

1002424168.jpg

The National Youth Wing of the opposition African Democratic Congress, ADC) has written a formal petition against Justice Peter Odo Lifu, demanding his removal “from any and all adjudicatory matters, reviews, or decision-making roles concerning the ADC.”

The petition, dated June 18, 2026, was addressed to the Executive Secretary, National Judicial Council (NJC), and signed by the ADC’s national youth leader, Comrade Balarabe Rufai. 

While reading the content of the petition to media in front of the ADC National Secretariat, Comrade Rufai, who was represented by Comrade Ibrahim Garba Wala, alleged that there were attempts to prevent them from submitting the petition at the NJC. 

According to him, all roads leading to the NJC, on Thursday were barricaded by heavily armed security agents; hence, the need to present the petition to the public. 

The petition reads, “We demand the immediate, total removal of Hon. Justice Peter Odo Lifu from any and all adjudicatory matters, reviews, or decision-making roles concerning the ADC. Furthermore, given his pattern of flagrant judicial rascality, we explicitly demand that the National Judicial Council recommend his absolute dismissal from the Nigerian judiciary to preserve the fading credibility of the bench.

“Our democratic architecture is under a coordinated assault by compromised custodians of the law. Under suit number FHC/ABJ/CS/2637/2026, Hon. Justice Peter Odo Lifu delivered a highly controversial ruling ordering the Independent National Electoral Commission (INEC) to deregister the ADC and four other political parties. This judgment is not an honest legal error; it is a calculated, politically motivated act designed to shrink the democratic space in Nigeria and artificially consolidate a two-party monopoly.”

While lamenting what he described as “legal distortions and judicial rascality tying Justice Lifu to this systemic compromise,” the ADC Youth leader said, “Justice Lifu brazenly proceeded with this judgment despite a binding Court of Appeal order that explicitly stayed proceedings on this matter, a move that subverts the sacred doctrine of stare decisis and constitutes gross misconduct.”

“The bench looked away as the plaintiffs, the Incorporated Trustees of the National Forum of Former Legislators, clandestinely altered their legal personality midway through the process without a valid court order.

“While the NJC has previously dismissed certain claims due to standard procedural hurdles, the persistence of these identical accusations across multiple petitions—including those by the Chairman of the Boot Party—proves a systemic erosion of public trust.

“We cannot watch the political rights of millions of young Nigerians be auctioned off by compromised benches. The continuous involvement of Justice Lifu in ADC affairs completely destroys public trust and makes a mockery of fair hearings. As the protectors of our nation’s future, we declare that when the bench compromises its integrity, the youth will become the courtroom of public conscience. The ballot box belongs to us, and we will not allow any court to rob us of our political expression.”

“Until the Council acts to protect institutional integrity, enforces discipline, completely recuses this individual from our affairs, and begins the process for his immediate sack from the bench. Respectfully submitted on behalf of the Nigerian youth during a live protest.”

This comes as Lifu, in a judgment, ordered the Independent National Electoral Commission to deregister five opposition parties, including ADC. 

However, following widespread condemnation, the appeal court ordered a stay of execution of the judgment. 

Continue Reading

News

IPCR, SFCG urge action to save democracy from conflict drivers

info

Published

on

By

IMG 6006.jpeg

The Institute for Peace and Conflict Resolution (IPCR) and Search for Common Ground (SFCG) have called for efforts to address conflict drivers threatening democracy.

The organisations made the call on Thursday in Abuja at a joint news conference to commemorate the 2026 Democracy Day.

The Director-General of IPCR, Dr Joseph Ochogwu, said democracy remained the best form of government and depended on active citizen participation.

According to him, weak civic engagement, voter apathy and poor democratic culture continue to challenge democratic consolidation in Nigeria.

Mr Ochogwu said IPCR’s conflict assessments showed that many pressures on democracy stemmed from citizen disengagement rather than democracy itself.

He urged Nigerians, especially youths, to participate actively in elections and governance processes to strengthen democratic institutions.

The IPCR boss described electoral violence, intimidation and coercive political practices as serious threats to democratic development.

He called on political actors, electoral institutions, security agencies, media organisations and civil society groups to promote peaceful political engagement.

Mr Ochogwu also expressed concern over the increasing monetisation of politics, saying it excluded ordinary citizens from meaningful participation.

He identified terrorism, banditry, organised crime and violent extremism as major threats undermining governance and public confidence in institutions.

Responding to questions, Mr Ochogwu said insecurity would not prevent the conduct of elections in 2027.

He urged Nigerians not to lose hope in the country and to continue supporting democratic processes.

The Director of Programmes, Search for Common Ground,  Gift Omoniwa, said protecting democracy required addressing insecurity and conflict drivers.

Mrs Omoniwa said banditry, kidnapping and violent extremism continued to threaten peace, stability and democratic governance across Nigeria.

She stressed the need for inclusive approaches that address root causes of conflict and promote peaceful coexistence.

According to her, vulnerable youths remain targets for recruitment by violent groups, posing risks to national security and democracy.

She advocated greater youth empowerment, economic opportunities and meaningful participation in governance processes.

Mrs Omoniwa disclosed that SFCG and IPCR recently conducted conflict assessments in Benue, Nasarawa, Plateau and Taraba states.

She said the findings were being shared with stakeholders to support evidence-based interventions and conflict prevention efforts.

The interventions include strengthening early warning systems, peace committees and livelihood programmes in affected communities.

Mrs Omoniwa expressed confidence that the measures would support peaceful and credible elections in 2027.

She reaffirmed SFCG’s commitment to working with government institutions, civil society groups and communities to promote peace and democratic governance. 

(NAN)

Continue Reading

Trending