
Together AI has taken immediate action to address the Copy Fail vulnerability (CVE‑2026‑31431) by disabling the affected crypto socket interface across its infrastructure. This logic bug in the Linux kernel allows unprivileged local users to exploit the system, posing significant risks in multi-tenant AI environments. The company has implemented a strategy to unload the vulnerable module and prevent its reactivation, while also preparing to roll out kernel patches once they are available. This proactive approach aims to enhance the security of AI workloads and mitigate potential cross-tenant risks.
Read original