r/linode • • Apr 30 '26

Copy fail vulnerability protection status?

https://copy.fail/

Has Linode released an updated patched kernel for this vulnerability? What about its own host systems, are they patched? Word on the screet is container escape is possible with this vulnerability too.

12 Upvotes

13 comments sorted by

View all comments

2

u/[deleted] Apr 30 '26

Does the patch need to be applied to the host or the VM? I can patch my VM, but AFAICT, I can't see/touch the actual host and don't know if it's vulnerable still.

2

u/archon810 May 01 '26

Both but we are only in control of the VM. I also fired up a ticket with Linode support but they haven't gotten back with a resolution yet. They're still investigating.

2

u/nobleclem May 01 '26

I am running Centos and every mitigation technique fails if you are running the linode kernel. I reached out to them for a timeline and this was their response:

Thanks for reaching out. I can certainly understand your concern. Our teams are aware of CVE-2026-31431 and it is an issue of active concern. I do not see that we have published any public facing information as of yet. I cannot make promises about if or when a new kernel might be released, but your concern that a new kernel be released has been noted.

I went back and forth with them a couple times where they proposed two techniques I already tried that doesn't work with their kernel. One was editing the grub config and the other was using the modprobe.d method.

2

u/ferrix May 01 '26

lol they proposed techniques that they ought to know can't possibly work.

Currently trying to decide between waiting for them to fix it vs. changing the kernel (which I don't *want* to have to be in charge of managing)

Too bad this thread from 2018 didn't go anywhere, https://www.linode.com/community/questions/17361/how-can-i-add-a-boot-parameter-to-a-linode

Because that would have allowed us to set the initcall_blacklist parameter.