# Two More Major Linux Vulnerabilities Discovered in the Same Class as Copy Fail

**URL:** https://discuss.privacyguides.net/t/two-more-major-linux-vulnerabilities-discovered-in-the-same-class-as-copy-fail/37746
**Category:** News
**Created:** 2026-05-08T18:20:45Z
**Posts:** 12

## Post 1 by @fria — 2026-05-08T18:20:45Z

Two new Linux local privilege escalation vulnerabilities, [Dirty Frag](https://github.com/V4bel/dirtyfrag/blob/07995be9d940f826deb0e9faa6d9f6e8fe2535e7/assets/write-up.md) and [Copy Fail 2: Electric Boogaloo](https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo) were discovered in the same vulnerability class as [Copy Fail](https://copy.fail), affecting most Linux distributions.

* * *
This is a companion discussion topic for the original entry at [https://www.privacyguides.org/news/2026/05/08/two-more-major-linux-vulnerabilities-discovered-in-the-same-class-as-copy-fail](https://www.privacyguides.org/news/2026/05/08/two-more-major-linux-vulnerabilities-discovered-in-the-same-class-as-copy-fail)

---

## Post 2 by @anon7180143 — 2026-05-08T18:38:16Z

> [@fria](#):
>
> Perhaps the Linux kernel maintainers and Linux distributions could do more to protect their users against such attacks before they’re found.

Do they not have access to the likes of Mythos like Mozilla does?

> [@fria](#):
>
> So many high-severity bugs in such a short time is alarming.

I used to think the show Person of Interest was way out there and no way things are that vulnerable. I see now it was way ahead of its time and I was wrong. Makes for a better show now. Ironic cause shows with tech don’t usually age well.

---

## Post 3 by @any1 — 2026-05-08T18:43:06Z

> [@anon7180143](#):
>
> Do they not have access to the likes of Mythos like Mozilla does?

> **[Project Glasswing: Securing critical software for the AI era](https://www.anthropic.com/glasswing)**
>
> A new initiative to secure the world’s most critical software and give defenders a durable advantage in the coming AI-driven era of cybersecurity.

> Today we’re announcing Project Glasswing1, a new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software.

---

## Post 4 by @anon7180143 — 2026-05-08T18:44:09Z

Ah! Thanks for sharing.

So that’s good then, no? More findings means more fixes.

Just imagine if that XZ Utils guy had this before. Linux would have been cooked by now. He was so close.

---

## Post 5 by @Lukas — 2026-05-08T20:08:32Z

Daniel Micay and Madaidan are pretty much completely vindicated.

The article is 4 years old, but all the issues are still there: [Linux | Madaidan's Insecurities](https://madaidans-insecurities.github.io/linux.html)

This should make it obvious that Linux desktop security isn’t fine at all, like some like to claim, and that Linux phones are a terrible idea until the security posture of Linux distributions is drastically improved.

---

## Post 6 by @FranklyFlawless — 2026-05-09T00:59:18Z

I am slowly working on it.

---

## Post 7 by @anonymous549 — 2026-05-09T01:12:10Z

> [@fria](#):
>
> Two new Linux local privilege escalation vulnerabilities, [Dirty Frag](https://github.com/V4bel/dirtyfrag/blob/07995be9d940f826deb0e9faa6d9f6e8fe2535e7/assets/write-up.md) and [Copy Fail 2: Electric Boogaloo](https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo)

These names :skull_and_crossbones:

---

## Post 8 by @anonymous568 — 2026-05-10T07:18:21Z

> [@fria](#):
>
> Perhaps the Linux kernel maintainers and Linux distributions could do more to protect their users against such attacks before they’re found.

The more Linux gets popular, the more targeted it will be as well. If Linux wants to succeed in market share, they _need_ to up their security. The moment it gains large adoption, one single catastrophic exploit could make people run back to Windows or Mac.

---

## Post 9 by @FranklyFlawless — 2026-05-10T08:23:53Z

Understood.

---

## Post 10 by @seize — 2026-05-10T13:33:30Z

I see your point, though it isn’t like these catastrophic exploits don’t exist on Windows MacOS either.

> The moment it gains large adoption, one single catastrophic exploit could make people run back to Windows or Mac

Not to be _that guy_ but Linux already has mass adoption thanks to server/infrastructure market so there is already significant incentive from various parties to find vulnerabilities, create exploits and patch said vulnerabilities and exploits.

I agree that Linux needs to up its security for any significant success in the desktop market share but I’m not sure how many people outside of online privacy and security spaces would be aware of, and care enough to move OSes when these critical OS vulnerabilities are found even if they did make the switch to Linux.

---

## Post 11 by @anonymous568 — 2026-05-10T16:10:28Z

> [@seize](#):
>
> isn’t like these catastrophic exploits don’t exist on Windows MacOS either

Yes, you’re right to say that they do have catastrophic exploits. However, my point in saying this was that Windows and Mac are the cultural default. If the alternative doesn’t match what the cultural default provides, there are two things that this could happen:

1. The cultural paradigm shifts to reflect the fact that people actually prefer the alternative

This is the ideal case for Linux—that the public actually prefers Linux over Windows for some set of reasons.

1. The alternative remains only that: a cultural alternative

This is the less-than-ideal case. Linux remains only as an alternative that appeals to a niche community of desktop/laptop users.

Even though all three operating systems have catastrophic exploits from time to time, two of them are given the status of “normal” and are part of everyday culture while the third one is neither. At least in the US. Maybe it is different in European countries. I remember seeing some institutional adoption of open-source tech, which is another metric that measures cultural adoption.

> [@seize](#):
>
> I’m not sure how many people outside of online privacy and security spaces would be aware of, and care enough to move OSes when these critical OS vulnerabilities are found even if they did make the switch to Linux

Moving from the cultural default to a cultural alternative takes a lot of intention. Meanwhile, moving from the alternative to the default is very easy and incentivised because there is less friction between you and the cultural and social world you inhabit. If there _were_ people who moved to Linux and found out that they were exploited or hacked, it’s not a matter of caring enough to switch. If I try a new food and it I don’t like how it tastes, I go back to eating the food I usually eat. But I take your point that a lot of people outside this space probably won’t be _aware_ that their devices were exploited.

> [@seize](#):
>
> Linux already has MA’s adoption thanks to server/infrastructure market so there is already significant incentive from various parties to find vulnerabilities, create exploits and patch said vulnerabilities and exploits

You’re completely right. I forgot about the infrastructure market.

---

## Post 12 by @seize — 2026-05-10T16:34:31Z

> [@anonymous568](#):
>
> Even though all three operating systems have catastrophic exploits from time to time, two of them are given the status of “normal” and are part of everyday culture while the third one is neither. At least in the US.

I think this largely comes down to what you define as a “cultural default”. Personally I view Linux desktop adoption more at an individual level, which could eventually affect some “cultural default” instead of viewing the “cultural default” before individual choice.

I would also like to say that we(I) consider MacOS and Windows “normal” and the “cultural default” largely because they ship as the default software on the hardware we purchase, and since most people will never install their own OS, or even perhaps know this is an option, Desktop Linux market share is limited in its growth. This is why I am hopeful that hardware that ships with Desktop Linux _by default_[[1]](#footnote-153467-1) eventually take off.

* * *

1. Various OEMs are making progress on this like Framework, System76, and to some extent traditional OEMs like DELL or Lenovo, but Windows is still the majority default by a significant margin. [↩︎](#footnote-ref-153467-1)
