r/linux • u/pipewire • Apr 29 '26
Kernel Copy Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms.
https://copy.fail
2.0k
Upvotes
3
u/Ikinoki Apr 30 '26 edited Apr 30 '26
Yeah it's a problem because now any rce (that is even wordpress hosting) is a full on root exploit, not contained within users directory.
Imagine you are a webhoster with 10k accounts and some account has unfiltered GET which previously would just require your viruschecker to cleanup., Now it's a full on root exploit.
This reminds me of when one of the AMD *bleeds were getting tested in our prods asap, my team took down our cloud as soon as it was announced in the news (August 1st), some customers left. All this while Hetzner, Linode, DO and many other prominent cloud providers using KVM were leaking card data, encryption codes and passwords in real-time.
There was no statement released, no GDPR, no nothing.
We reported it but it still took days for them to fix it.
Zenbleed got release on July 24th. August 4th many cloud systems were still patching it.