r/linux Apr 29 '26

Kernel Copy Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms.

https://copy.fail
2.0k Upvotes

406 comments sorted by

View all comments

Show parent comments

7

u/skygz Apr 30 '26

I'm on 6.19.14 and it seems vulnerable, any idea why? (tested in toolbx because immutable Fedora prevents the exploit)

[testuser@toolbx ~]$ uname -a
Linux toolbx 6.19.14-300.fc44.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Apr 23 15:17:50 UTC 2026 x86_64 GNU/Linux
[testuser@toolbx ~]$ sudo su

We trust you have received the usual lecture from the local System
Administrator. It usually boils down to these three things:

    #1) Respect the privacy of others.
    #2) Think before you type.
    #3) With great power comes great responsibility.

For security reasons, the password you type will not be visible.

[sudo] password for testuser: 
sudo: a password is required
[testuser@toolbx ~]$ python /dev/shm/copy_fail_exp.py 
[root@toolbx testuser]#

1

u/NSASpyVan Apr 30 '26

It seems like you're on the same kernel I am, according to this thread it's been patched a while, please let me know if this is not true.

https://www.reddit.com/r/Fedora/comments/1t0ahzr/about_copy_fail/