This critical vulnerability affects Linux Kernel versions 4.14 through 6.19.12, it impacts major linux distributions including Ubuntu, Debian, and Red Hat. This allows a low privileged user within a linux shell environment to gain root access over the system. This is done through a 732 byte script that targets the AF_ALG socket that exposes the kernel's crypto subsystem to an unprivileged user space.
| Product Name | Affected Versions | Fixed Version |
|---|---|---|
| Linux Kernel | 4.14 (2017) - 6.19.11 | 7.0, 6.19.12, 6.18.22, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254 |
- Initial Report: A cybersecurity researcher, Taeyang Lee, had already knew about a flaw in the AF_ALG + splice path that creates an unprivileged userspace into the crypto subsystem. He then passed his concerns into an AI agent called xint code which audited the entire subsystem and found Copy Fail after an hour of running.
- Vendor Notification: April 26, 2026
- Patch Release: Patches were released starting April 30, 2026
- Active Exploitation: CISA added this CVE to their known exploited vulnerabilities catalog in May 1, 2026