Connect with us

News

US government warns of severe CopyFail bug affecting major versions of Linux

info

Published

on

Lukas NLSXFjl nhc unsplash.jpg

A severe security vulnerability affecting almost every version of the Linux operating system has caught defenders off-guard and scrambling to patch after security researchers publicly released exploit code that allows attackers to take complete control of vulnerable systems.

The U.S. government says the bug, dubbed “CopyFail,” is now being exploited in the wild, meaning it’s being actively used in malicious hacking campaigns.

The bug, officially tracked as CVE-2026-31431 and discovered in Linux kernel versions 7.0 and earlier, was disclosed to the Linux kernel security team in late March, and patched after about a week. But the patches have yet to fully trickle down to the many Linux distributions that rely on the vulnerable kernel, leaving any system running an affected Linux version at risk of compromise.

Linux is widely used in enterprise settings, running the computers that operate much of the world’s datacenters. 

The CopyFail website says that the same short Python script “roots every Linux distribution shipped since 2017.”  According to security firm Theori, which discovered CopyFail, the vulnerability was verified in several widely used versions of Linux including Red Hat Enterprise Linux 10.1, Ubuntu 24.04 (LTS), Amazon Linux 2023, as well as SUSE 16. 

Devops engineer and developer Jorijn Schrijvershof wrote in a blog post that the exploit works on Debian and Fedora versions, as well as Kubernetes, which relies on the Linux kernel. Schrijvershof described the bug as having an “unusually big blast radius” as it works on “nearly every modern distribution” of Linux.

The bug is called CopyFail because the affected component in the Linux kernel, the core of the operating system that has virtually complete access to the entire device, does not copy certain data when it should. This corrupts sensitive data within the kernel, allowing the attacker to piggyback the kernel’s access to the rest of the system, including its data.

If exploited, the bug is particularly problematic because it allows a regular, limited-access user to gain full-administrator access on an affected Linux system. A successful compromise of a server in a datacenter could allow an attacker to gain access to every application, server, and database of numerous corporate customers, and potentially gain access to other systems on the same network or datacenter.

The CopyFail bug cannot be exploited over the internet on its own, but can be weaponized if used in conjunction with an exploit that works over the internet. Per Microsoft, if the CopyFail bug is chained together with another vulnerability that can be delivered over the internet, an attacker could use the flaw to gain root access to an affected server. A user operating a Linux computer with a vulnerable kernel could also be tricked into opening a malicious link or attachment that triggers the vulnerability.

The bug could also be injected by way of supply chain attacks, in which malicious actors hack into an open source developer’s account and plant the malware in their code in order to compromise a large number of devices in one go.

Given the risk to the federal enterprise network, U.S. cybersecurity agency CISA has ordered all civilian federal agencies to patch any affected systems by May 15.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Police rescue 10 passengers after bandits attack Jos-Kano highway bus

info

Published

on

By

Police 2.jpg

Bandits abducted 13 passengers travelling in a commercial bus along the Jos-Kano highway in Doguwa Local Government Area of Kano State, but police operatives rescued 10 of the victims after engaging the attackers in a gun battle.

The incident occurred on Sunday at about 5:30 pm at the Folgore Forest axis, between Gate Two Safer Highway and Dogo Dutse.

The Kano State Police Command, in a statement issued on Monday by its spokesperson, CSP Abdullahi Haruna Kiyawa, said the Divisional Police Officer (DPO) of Doguwa Division received a distress call that a Toyota Hiace bus travelling from Jos to Kano had been attacked by armed men.

According to the statement, five suspected bandits armed with machetes and a firearm blocked the road, attacked the bus and abducted 13 of the 20 passengers on board.

The police said the DPO immediately mobilised tactical operatives to the scene, where they confronted the attackers in a gun duel.

“As a result of the swift and coordinated response of the Police team, nine victims were successfully rescued. One other male victim later escaped from captivity,” the statement said.

The command, however, disclosed that three victims, comprising one man and two women, were still being held by the kidnappers.

It added that the rescued passengers were taken to Doguwa General Hospital for medical evaluation and were in stable condition while receiving treatment.

The police said additional tactical teams had been deployed to the area, while intelligence gathering and search operations had been intensified to secure the release of the remaining captives and arrest those responsible for the attack.

The Commissioner of Police in Kano State, Ibrahim Adamu Bakori, commended residents and road users for providing timely information that helped the police respond quickly to the incident.

He assured residents that the command remained committed to protecting lives and property and urged members of the public to continue reporting suspicious movements or activities to the nearest police station.

Continue Reading

News

2027: OK Movement gets new National Director General

info

Published

on

By

Peter Ameh 1200x720 1.jpg

The OK Movement has appointed a former Chairman of the Inter-Party Advisory Council, IPAC, Peter Ameh, as its National Director General ahead of the 2027 general elections.

The Movement made this announcement in a statement posted on its verified X handle on Monday.

“The OK Movement is pleased to announce the appointment of High Chief Peter Ameh, as the National Director General of the OK Movement.

“With his vast wealth of experience in politics, leadership, and nation-building, we are confident he will provide the strategic direction needed to strengthen the Movement and lead us towards victory,” the statement read.

This came after the Movement appointed the Director of the Abuja School of Social and Political Thought, Sam Amadi, as its Head of the Advisory Council.

DAILY POST reports that the OK Movement is a political group comprising the supporters of the Nigeria Democratic Congress, NDC, presidential candidate, Peter Obi, and his running mate, Rabi’u Kwankwaso.

Continue Reading

Trending