CVE-2026-31431: Copy Fail vs. rootless containers
Summary
A detailed analysis of CVE-2026-31431 (Copy Fail) in rootless containers, including shellcode analysis, lab setup, and how user namespaces constrain privilege escalation. The article demonstrates how root inside a container does not translate to host root, thanks to UID mappings, and highlights defense-in-depth via container isolation and monitoring.