<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ansible on Marco Lazzarotto</title><link>https://lazzarotto.dev/blog/en/tags/ansible/</link><description>Recent content in Ansible on Marco Lazzarotto</description><generator>Hugo</generator><language>en-us</language><managingEditor>postmaster@mlazzarotto.it (Marco Lazzarotto)</managingEditor><webMaster>postmaster@mlazzarotto.it (Marco Lazzarotto)</webMaster><copyright>Marco Lazzarotto</copyright><lastBuildDate>Fri, 01 May 2026 00:00:00 +0100</lastBuildDate><atom:link href="https://lazzarotto.dev/blog/en/tags/ansible/index.xml" rel="self" type="application/rss+xml"/><item><title>Mitigating the 'Copy Fail' Vulnerability (CVE-2026-31431) with a Simple Ansible Playbook</title><link>https://lazzarotto.dev/blog/en/mitigating-the-copy-fail-vulnerability-cve-2026-31431-with-a-simple-ansible-playbook/</link><pubDate>Fri, 01 May 2026 00:00:00 +0100</pubDate><author>postmaster@mlazzarotto.it (Marco Lazzarotto)</author><guid>https://lazzarotto.dev/blog/en/mitigating-the-copy-fail-vulnerability-cve-2026-31431-with-a-simple-ansible-playbook/</guid><description>&lt;p&gt;&lt;a class="link" href="https://github.com/mlazzarotto/copy-fail-CVE-2026-31431-mitigation-ansible-playbook" target="_blank" rel="noopener"
 &gt;Direct link to the Github repo&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="in-a-nutshell-theres-a-new-critical-linux-bug-going-around"&gt;In a nutshell: there&amp;rsquo;s a new critical Linux bug going around
&lt;/h2&gt;&lt;p&gt;&lt;a class="link" href="https://copy.fail/" target="_blank" rel="noopener"
 &gt;&amp;lsquo;Copy Fail&amp;rsquo;&lt;/a&gt; is a new and nasty local privilege escalation bug, &lt;a class="link" href="https://cert.europa.eu/publications/security-advisories/2026-005/" target="_blank" rel="noopener"
 &gt;CVE-2026-31431&lt;/a&gt;, discovered by the analyst team at &lt;a class="link" href="https://xint.io/products/xint-code" target="_blank" rel="noopener"
 &gt;Xint Code&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This bug essentially allows an attacker to gain &lt;em&gt;root&lt;/em&gt; privileges on many Linux operating systems (Ubuntu, Debian, RHEL, Suse, Alma, Amazon Linux) using a Python script of just 732 bytes.&lt;/p&gt;
&lt;p&gt;&amp;lsquo;Copy Fail&amp;rsquo; only requires a local unprivileged user account: no network access, no kernel debug capabilities, no pre-installed libraries. The kernel&amp;rsquo;s cryptographic API (AF_ALG) is enabled by default on virtually all major distributions, meaning the entire patch range from 2017 onward is vulnerable.&lt;/p&gt;</description></item></channel></rss>