June 4, 2026

PBX Science

VoIP & PBX, Networking, DIY, Computers.

Parrot OS 7.2 Released: Copy Fail Patch, 15 Updated Tools, and a New HTB Image

Parrot OS 7.2 Released: Copy Fail Patch, 15 Updated Tools, and a New HTB Image



Parrot OS 7.2 Released — Security Edition
Linux & Security

Parrot OS 7.2 Released: Copy Fail Patch, 15 Updated Tools, and a New HTB Image

The Parrot Project ships its second update to the 7.x series, prioritising a critical kernel privilege-escalation fix and a sweeping refresh of the penetration-testing toolchain.

May 9, 2026 · Security / Linux · Parrot Project · ~4 min read
Version 7.2
Kernel Linux 6.19.13
Base Debian 13.4 “Trixie”
Default DE KDE Plasma
Tools Updated 15

The Parrot Project released Parrot OS 7.2 on May 9, 2026, delivering the second update to its 7.x series. While the release gathers months of rolling updates, its primary focus falls on infrastructure improvements, Docker container refinements, and a broad security-tool refresh. Crucially, it ships Linux kernel 6.19.13—carrying a patch for a high-impact local privilege-escalation flaw that matters deeply to the distribution’s core audience of penetration testers and security researchers.

🔐 Critical Kernel Security Fix

The most urgent reason to update is the kernel. Parrot OS 7.2 adopts Linux 6.19.13, which resolves a recently disclosed privilege-escalation vulnerability affecting the kernel’s cryptographic subsystem.

CVE-2026-31431 — “Copy Fail”

Disclosed on April 29, 2026, this flaw resides in the algif_aead kernel module. An unprivileged local user can exploit it to write controlled bytes into the page cache of any readable file on the system, potentially gaining root privileges. The fix in Linux 6.19.13 closes this attack surface entirely.

The fix is particularly timely for Parrot’s users, who frequently work in environments where privilege escalation is both the target of their assessments and a genuine risk to their own machines. Running an unpatched kernel while actively testing for privilege-escalation vulnerabilities on client infrastructure is an uncomfortable position—this release resolves that.

🛠 15 Updated Security Tools

Parrot OS 7.2 delivers version bumps across the full penetration-testing toolchain. Exact version numbers confirmed in official release notes are listed below.

NetExec
→ 1.5.1
OWASP ZAP
→ 2.16.1
BloodHound
→ 9.0.0
BeEF-XSS
→ 0.6.0.0
Certipy AD
→ 5.0.4
Evilginx
→ 3.3.0
Evil-WinRM-py
→ 1.6.0
SQLMap
→ 1.10.3
Metasploit
→ 6.4.127
MCPwn
→ 1.2.0
enum4linux-ng
→ 1.3.5
GDB GEF
→ 2026.01
Legion
→ 0.7.0
httpx-toolkit
→ 1.7.4
pypsrp
→ 0.8.1

🖥 Desktop and System Improvements

Parrot OS 7.0 introduced KDE Plasma as the default desktop environment, replacing MATE. Parrot 7.2 continues with KDE Plasma, though the official release notes do not specify the precise component version numbers (Plasma, Frameworks, Qt) shipping in this release. MATE and LXQt spins remain available alongside the Enlightenment spin that debuted in Parrot 7.1.

On the system side, the Parrot Menu is progressing through its migration to a new Go-based codebase, with additional desktop entries added in this release. The parrot-themes and parrot-tools packages have also been refreshed. A notable quality-of-life addition: parrot-core now includes a built-in Flatpak package check that automatically manages Flatpak updates without requiring manual intervention.

The virtual machine codebase has been refactored for improved modularity and readability. The Parrot website and documentation are also undergoing a design overhaul, with several sections already revised for clarity.

📦 Debian 13.4 “Trixie” Synchronisation

As a Debian-derivative, Parrot OS 7.2 synchronises with Debian 13.4 “Trixie” upstream, ensuring all core packages incorporate the latest security patches and stability fixes from the broader Debian ecosystem. Parrot’s security-focused package set remains aligned with this Debian base.

📋 Available Editions

🔴 Security Edition

Ships with the full suite of pre-installed penetration testing and cybersecurity tools. Aimed at security professionals, researchers, and red teamers who need a ready-to-go offensive environment.

🔵 Home Edition

Designed for everyday use, privacy, and development. Provides a clean system without the full security toolset by default; individual tools can be installed as needed.

🟣 Hack The Box (HTB) Edition — New in 7.2

Parrot OS 7.2 adds image generation support for the Hack The Box Edition in both ISO and virtual machine formats, enabling quick deployment in HTB lab and CTF environments without manual configuration.

Beyond these desktop editions, the project also offers pre-packaged Docker images, VM images, a WSL image, a Raspberry Pi image, and a RISC-V edition.

Editorial note on accuracy: Some third-party summaries of this release cited specific KDE component version numbers (Plasma 6.3.6, Frameworks 6.13, Qt 6.8.2) that are not confirmed in the official Parrot release notes. This article omits those unverified figures. All tool version numbers and feature descriptions above are sourced directly from the official Parrot Project announcement and verified secondary reporting.
Parrot OS 7.2 is available now parrotsec.org — Home, Security, HTB, Docker, VM, WSL, Raspberry Pi & RISC-V images
Download →
© 2026 Security News · Parrot OS 7.2 Release Coverage Sources: parrotsec.org · 9to5linux · ubuntupit · linuxiac

Parrot OS 7.2 Released: Copy Fail Patch, 15 Updated Tools, and a New HTB Image

Parrot OS 7.2 Released: Copy Fail Patch, 15 Updated Tools, and a New HTB Image


Windows Software Alternatives in Linux


Disclaimer of pbxscience.com

PBXscience.com © All Copyrights Reserved. | Newsphere by AF themes.