A new Linux kernel zero-day called CopyFail lets code break out of containers onto the host. We took a close look at our community hubs, confirmed they're likely safe, and added another layer of protection just in case. Here's a post about what we learned 👉 2i2c.org/blog/copyfai...
Protecting our hubs against the CopyFail kernel exploit | 2i2c
The recently disclosed CopyFail Linux kernel zero-day (CVE-2026-31431) opens up a way for code running inside a container to break out onto the underlying node. We took a close look at our hubs to…
2i2c.org