oss-sec mailing list archives

Re: CVE-2026-31431: CopyFail: linux local privilege scalation


From: Paul Ducklin <pducklin () outlook com>
Date: Sun, 3 May 2026 18:06:38 +0000

So one solution would be to get the
fingers-of-one-hand applications still
using the interface off it onto user-mode
software-only and then make it
kernel-only, closing the door on the entire
attack surface from user space

Perhaps the mantra, “never break user space” needs rewriting as, “break user space only when something is already 
broken” (such as when the number of CVEs already associated with that thing exceeds some smallish positive integer N, 
say, 5).

Duck

Current thread: