Skip to content

Ubuntu 24 GitHub Actions Runner Vulnerability Mitigations for CVE-2026-31431 ("Copy Fail") #4409

@ZachEndWesco

Description

@ZachEndWesco

We have observed that the GitHub Actions runners are still using Ubuntu 24, which is known to be vulnerable to the recently disclosed CVE-2026-31431 ("Copy Fail") vulnerability.
As we are using the latest version of the runners, we are concerned about the potential security risks associated with this issue. Could you please clarify:

  1. Are there any mitigations already in place for this vulnerability on the current runner images?

  2. If not, what steps are being taken to address this vulnerability, and is there an expected timeline for a patched version of the runner images?

  3. Are there any steps we can take to mitigate the risk partially or fully ourselves?

Thank you in advance for your time.

Runner Version and Platform

ARC Version 0.14.1
ARC Scaleset version 0.14.1
actions runner image version 2.334.0

OS of the machine running the runner? OSX/Windows/Linux/...
Ubuntu 24

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions