CopyFail: From Pod to Host
Copy Fail (CVE-2026-31431) is a critical Linux kernel vulnerability enabling deterministic attacks across container boundaries in Kubernetes environments, allowing attackers to poison shared files in the page cache or escape containers to gain host root access without traditional code injection. The vulnerability exploits kernel memory corruption through IPSec cryptography interfaces, making it particularly dangerous because compromises remain invisible to disk-based security scanners and can spread between containers sharing image layers. IT organizations must immediately assess their Kubernetes infrastructure exposure and patch vulnerable systems, as the attack requires minimal privileges (pod creation rights) and can be executed from freshly-launched attacker pods.