We're sharing this writeup because we think transparency about security work matters. If you run JupyterHub on Kubernetes, this might save you some investigation time.
👉 2i2c.org/blog/copyfai...
2i2c.org
Protecting our hubs against the CopyFail kernel exploit | 2i2c
The recently disclosed CopyFail Linux kernel zero-day (CVE-2026-31431) opens up a way for code running inside a container to break out onto the underlying node. We took a close look at our hubs to…