Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a21dc202da54cf89

Jump to content

Talk:Copy Fail

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 2 months ago by ~2026-27057-31 in topic Culprit and Patching

few notes

[edit]

Hi folks. Wanted to start a discussion on a few content points:

  • should we be using the https://copy.fail advisory or the full write-up at https://https://xint.io/blog/copy-fail-linux-distributions ? The write-up is far more detailed about the causes of the exploit, but has even worse promotional tone than the advisory. I'd be happy to wait until people start making less-promotional independent write-ups.
  • I've removed the patch date - many distributions are still not shipping patched kernels, such as RHEL and its derivatives. Does that make sense? Is there a way to include multiple patch dates in a bug infobox, so that we could include one for a kernel patch date and one for when that patch actually makes it out to distributions?
  • I've found several primary, non-reliable sources claiming that the discoverers disclosed the exploit to the kernel devs, but not to any distribution maintainers, leading to this rush after public disclosure to get the patched kernel into distributions. I've been reading to see if this is verified in any reliable sources - would appreciate additional help with that.

Eyesinthefire (talk) 17:17, 1 May 2026 (UTC)Reply

I was hoping for something more exact than "or newer" for a fixed in version, actually the current text makes it sound like this will never be fixed :/ Can I take this to mean to pull from git and even if that's the case, wouldn't a commit ID be more accurate? Cheako (talk) 17:32, 1 May 2026 (UTC)Reply
That's separate from what I'm asking of the patch date, but that needs to be fixed too. It's fixed in upstream kernel stable version 7.0.0.
What I'm asking about regarding the patch date is that as far as I understand, at least Debian and Arch have already backported the patch to their kernel releases of 6.19.12 and newer, but at least RHEL and Ubuntu haven't.
The commit ID is only the reference to the patch itself and doesn't give any details of where that patch has been applied. I don't think we should include it in the article (and I don't think the discoverers should have had that as the only reference to what versions were fixed in their advisory...)
Eyesinthefire (talk) 17:39, 1 May 2026 (UTC)Reply
The writeup is clearly linked from the copy.fail homepage. I would like to only have one link (duplicated the EL section and infobox), the copy.fail one makes most sense to me.
Patch date should be removed indeed, this is one big mess, there is no clear date.
Will try to add more info on the mess around the disclosure procedure once a reliable secondary reference for it found, I agree it would be desirable to include. PhotographyEdits (talk) 18:03, 1 May 2026 (UTC)Reply
point 1. i would keep copy.fail on infobox and add blog link in external section
point 2.
from what i understand patch date is referring to source software patched date. patch date for linux distribution can be added on body of the page
from copy.fail it state it is first april
https://www.tenable.com/blog/copy-fail-cve-2026-31431-frequently-asked-questions-about-linux-kernel-privilege-escalation
also first april
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
author date is 26 march, but commit date is 31 march
point 3. https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/
Linux distributors frequently stick with older kernel versions and backport fixes into them. There’s no indication in the disclosure deadline that Theori ever contacted the distributors. With the exploit available before fixed distributions were available, the disclosure amounts to something very similar to a zero-day vulnerability being dropped, although the stiffer term is probably “zero-day patch gap.” Lokiretro (talk) 13:47, 2 May 2026 (UTC)Reply
1. I agree with PhotographyEdits that having a single one rather than both the copy.fail and xint blog would be preferable per WP:ELMIN
2. I think the best option may be Apr 11 2026 as the release date of upstream stable version 6.19.12 (first stable version with patch included) rather than any date of the patch being put into the git master branch.
3. good eye!
Eyesinthefire (talk) 17:01, 2 May 2026 (UTC)Reply
[edit]

Some related articles/links for research/citations:

--Posted by Pikamander2 (Talk) at 21:57, 1 May 2026 (UTC)Reply

Culprit and Patching

[edit]

Can we add a link to the original git that added this vulnerability? (and one that fixes it in the base Linux kernel)

I'm also missing a more technical (short) description of the issue.

Also, a list of distros with their patching state would be useful. Maybe not only Debian, Ubuntu, RHEL, but also some others like Busybox, pfSense and similar. ~2026-27057-31 (talk) 09:12, 5 May 2026 (UTC)Reply

Update: I've started a table. Feel free to extend it.  Preceding unsigned comment added by ~2026-27057-31 (talk) 09:24, 5 May 2026 (UTC)Reply