On 29 April 2026, Theori dropped a working proof-of-concept for a Linux kernel local privilege escalation that runs unmodified on Ubuntu, RHEL, Debian, SUSE, Amazon Linux, Fedora, and most everything else. No race condition. No per-distro offsets. The file on disk is never modified. AIDE, Tripwire, and every other checksum-based watchdog you trust to catch tampering sees nothing. If your cybersecurity program leans on file integrity monitoring as a last line of defense, you just lost it.
The bug is called copy.fail. It abuses the kernel crypto API (AF_ALG sockets) plus splice() to write four bytes at a time straight into the page cache of a file the attacker does not own. Bruce Schneier called it the worst Linux vulnerability in years, and that framing is not hyperbole. It is a kernel primitive that turns any local user into root on a machine you probably patched last week.
“The file on disk is never modified. AIDE, Tripwire and checksum-based monitoring see nothing.” — Theori advisory, April 2026

Copy.Fail Writes Where No Watchdog Looks
Here’s why this one stings. Most security hardening playbooks assume the kernel is the trust anchor, and the file system is what attackers tamper with. Integrity tools watch /etc/passwd, /etc/shadow, sudoers, sshd_config, the usual suspects. If anything writes to those files, you get an alert.
Copy.fail never touches the files. It edits the in-memory page cache the kernel uses to serve those files. Reads hit the modified version. Writes from a legitimate process get clobbered. The on-disk inode keeps its original SHA-256. Your nightly Tripwire run is happy. Your SIEM is happy. The attacker is root.
That is a strict upgrade in stealth over the usual local privilege escalation pattern, and it lands at the exact moment two other stories are reminding everyone that trusted artifacts are the new attack surface. The Shai-Hulud npm campaign shipped signed malicious TanStack and Mistral packages, which is to say packages that passed every signature-based check developers were told to run. And Hugging Face models can be weaponized with a single file tweak to the tokenizer library, hijacking model outputs and exfiltrating data from anyone who pulls them.
The connective tissue is brutal. Signature verification, file integrity monitoring, package signing, model provenance: these are the controls security teams have been told for years are the answer to supply chain and tampering risk. In May 2026, attackers have working bypasses for all of them simultaneously.
Why Your Cybersecurity Stack Misses It
Defense in depth was supposed to handle this. The idea was simple: if one control fails, another catches the attacker. The problem is most enterprise stacks have layered controls that all look at the same thing from slightly different angles. File hash on disk. File hash in backup. File hash in vulnerability scanner. Signed package metadata. Signed commit history.
All of those collapse the moment the attacker operates at a layer beneath them. Copy.fail operates in the page cache. Shai-Hulud operates inside the trusted developer’s signing keys. The Hugging Face attack operates inside a single file the model loader is contractually required to trust.
Threat detection that depends on artifact integrity is checking the wrong thing. What you actually need is behavioral telemetry, which is where most environments are weakest. Process lineage, syscall patterns, unusual writes to memory regions, sudden privilege transitions, lateral movement after a workload spawns an unexpected child. None of those rely on the file being modified, the signature being broken, or the firewall catching the inbound. They rely on noticing that a process is doing something a process of its kind should not do.
If your incident response runbook for “did anyone tamper with sshd” still starts with “compare the hash to the gold image,” update it. The hash will match. The binary in memory will not.
What to Do Before the Public PoC Spreads
You cannot wait for a clean patch to propagate across every kernel in your fleet. Treat this as a control problem, not just a patching problem. Here is the immediate work, ordered by impact.
- Restrict AF_ALG socket access. The exploit needs the kernel crypto socket family. If your workloads don’t use it, block it with seccomp profiles or a SELinux/AppArmor deny. Container runtimes can drop this capability per-pod.
- Audit who can splice() into kernel pipes from unprivileged contexts. Modern eBPF tools let you trace splice() calls by process. Anything calling it from a non-root user against a privileged file descriptor is suspicious.
- Move integrity monitoring into memory. IMA (Integrity Measurement Architecture) with appraisal in enforce mode catches modifications to runtime-loaded binaries the way Tripwire was supposed to but doesn’t. It’s not a free win, but it raises the bar substantially.
- Patch when your distro ships the fix, and verify the kernel version on every host afterward. Don’t trust the package manager’s word. uname -r after reboot, in a config-management report you actually read.
- Hunt retroactively for privilege escalations you can’t explain. Process auditd records, sudo logs, and EDR telemetry from the last 60 days. Look for short-lived root processes spawned from unprivileged users with no corresponding sudo entry.
- Re-pin developer dependencies and check lockfile diffs. Shai-Hulud’s signed-package trick means even your supply chain SBOM is suspect for anything pulled in the last two weeks. npm audit signatures is not enough. Diff what changed against what should have changed.
For the ongoing work, the harder shift is cultural. Stop treating “the signature is valid” or “the hash matches” as proof of safety. Those statements were always probabilistic, and the probability just moved against you. Behavioral controls, least privilege at the kernel level, and aggressive segmentation of who can run what on which host are the things that survive this class of attack. A firewall that limits which hosts can even reach a developer workstation is more useful than another endpoint integrity agent reporting that nothing changed.
The good news, such as it is, is that copy.fail requires local code execution. The attacker needs a foothold first. Brute-force prevention on SSH, phishing-resistant MFA on the front door, and tight egress controls on developer machines all reduce the number of preconditions an attacker can quietly assemble. The bad news is the local-execution bar is lower every year, and the controls that catch the post-exploitation step just got demonstrably weaker.
This is the kind of bug that quietly rewrites how you measure threat protection effectiveness. The teams that come out ahead are the ones who already invested in behavioral threat detection and treated artifact integrity as a useful signal rather than a verdict. The teams that didn’t are about to discover their dashboards were lying to them.
Sources
- Copy.Fail Linux Vulnerability — Schneier on Security
- Shai Hulud attack ships signed malicious TanStack, Mistral npm packages — BleepingComputer
- Hugging Face Packages Weaponized With a Single File Tweak — Dark Reading
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
