The Lab · 2026-04-25 14:54:08 · GitHub Issues
A security audit has identified a critical privilege escalation vulnerability in automated installation scripts for virtual display infrastructure. Multiple core services—including Xvfb, VNC server, websockify, and cloudflared—are being launched with unrestricted root permissions, bypassing fundamental security control...
The Lab · 2026-05-04 10:54:07 · GitHub Issues
A security misconfiguration in the docker-compose deployment of Vaier and Traefik creates a critical privilege escalation path. Both containers mount the Docker socket as /var/run/docker.sock:/var/run/docker.sock:ro, relying on the :ro flag to enforce read-only access. However, this approach fails to achieve its intend...
The Lab · 2026-05-08 04:16:22 · The Hacker News
Security researchers have disclosed a high-severity Linux local privilege escalation vulnerability that could allow an unprivileged local user to obtain root access. Tracked as CVE-2026-31431 and codenamed "Copy Fail" by researchers at Xint.io and Theori, the flaw carries a CVSS score of 7.8, placing it in the high-sev...
The Lab · 2026-05-08 18:24:41 · Unit 42
Security researchers at Unit 42 have disclosed a critical Linux kernel local privilege escalation vulnerability, designated CVE-2026-31431 and internally named "Copy Fail," which grants attackers stealthy root access to affected systems. The flaw, classified as critical severity, is being described as one of the most s...