
Proof-of-concept exploit for CVE-2026-31431 (Copy Fail), a Linux kernel LPE via algif_aead page-cache corruption, with detection, lab, and mitigation guidance.
██████╗ ██████╗ ██████╗ ██╗ ██╗ ███████╗ █████╗ ██╗██╗
██╔════╝██╔═══██╗██╔══██╗╚██╗ ██╔╝ ██╔════╝██╔══██╗██║██║
██║ ██║ ██║██████╔╝ ╚████╔╝ █████╗ ███████║██║██║
██║ ██║ ██║██╔═══╝ ╚██╔╝ ██╔══╝ ██╔══██║██║██║
╚██████╗╚██████╔╝██║ ██║ ██║ ██║ ██║██║███████╗
╚═════╝ ╚═════╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝╚═╝╚══════╝
algif_aead Page Cache Corruption⚠️ AUTHORIZED USE ONLY — This repository is strictly for penetration testers, security researchers, and defenders operating under lawful authorization. Misuse is a criminal offense.
| # | Section | Description |
|---|---|---|
| 1 | What is Copy Fail? | Vulnerability summary |
| 2 | Technical Deep Dive | Root cause analysis |
| 3 | Affected Systems | Distro & kernel matrix |
| 4 | Repository Structure | File layout |
| 5 | Lab Setup | Reproduce safely |
| 6 | Exploit Usage | Pentest workflow |
| 7 | Detection | YARA, Sigma, scripts |
| 8 | Mitigation | Patch & hardening |
| 9 | Pentest Reporting | Report templates |
| 10 | Legal & Ethics | Disclaimer |
| 11 | References | CVEs, advisories, blogs |
Copy Fail is a local privilege escalation (LPE) vulnerability disclosed on April 29, 2026, affecting virtually every major Linux distribution running kernels since 2017.
Unprivileged User ──► AF_ALG + splice() ──► 4-byte Page Cache Write ──► ROOT
| Property | Detail |
|---|---|
| CVE ID | CVE-2026-31431 |
| Nickname | Copy Fail |
| CVSS v3.1 | 7.8 (HIGH) |
| Attack Vector | Local |
| Privileges Required | Low (any unprivileged user) |
| User Interaction | None |
| Discoverer | Xint Code (Theori) |
| Disclosed | April 29, 2026 |
| Exploit Size | 732 bytes (Python PoC) |
| Patch Status | ✅ Available — revert commit a664bf3d603d |
The vulnerability stems from a buggy in-place optimization introduced in 2017 (commit 72548b093ee3) inside the algif_aead module of the Linux kernel's userspace crypto API (AF_ALG).
AF_ALG (userspace crypto API)
└── algif_aead module
└── authencesn template ◄── VULNERABLE
└── in-place optimization (2017)
└── req->src == req->dst ◄── pages from splice() chained into writable dst scatterlist
Step 1: Open AF_ALG AEAD socket
socket(AF_ALG, SOCK_SEQPACKET, 0)
Step 2: Send splice() pages referencing target file
(page cache pages of a privileged binary, e.g. /usr/bin/sudo)
Step 3: Trigger authencesn scratch write
authencesn uses dst buffer as scratch pad →
writes 4 controlled bytes PAST the legitimate output region
Step 4: Page cache entry for the target file is now corrupted
(disk file untouched — only in-memory copy modified)
Step 5: Execute the modified binary → ROOT
The Linux kernel's page cache backs in-memory copies of files. When a file is read, its pages are cached. The splice() syscall can reference these cached pages directly. By feeding page cache pages into the AF_ALG AEAD scatterlist, the authencesn scratch write lands inside those cached pages, effectively patching the in-memory copy of any readable file — including privileged binaries like sudo, pkexec, or passwd.
The upstream fix reverts the flawed 2017 optimization:
# Fixed in commit: a664bf3d603d
git show a664bf3d603d
| Kernel Branch | Affected? | Fixed Version |
|---|---|---|
| 4.9.x (LTS) | ✅ Yes | 4.9.340+ |
| 5.4.x (LTS) | ✅ Yes | 5.4.295+ |
| 5.10.x (LTS) | ✅ Yes | 5.10.239+ |
| 5.15.x (LTS) | ✅ Yes | 5.15.185+ |
| 6.1.x (LTS) | ✅ Yes | 6.1.132+ |
| 6.6.x (LTS) | ✅ Yes | 6.6.83+ |
| 6.12.x (LTS) | ✅ Yes | 6.12.19+ |
| < 4.9 (pre-2017) | ❌ No | N/A — optimization not present |
| Distribution | Affected Versions | Patched? | Advisory |
|---|---|---|---|
| Ubuntu | < 26.04 (all releases) | ✅ Patched | USN |
| Ubuntu 26.04 (Resolute) | ❌ Not affected | — | — |
| RHEL / CentOS | 7, 8, 9 | ✅ Patched | RHSA-2026 |
| Amazon Linux | 2, 2023 | ✅ Patched | ALAS |
| SUSE / openSUSE | All affected | ✅ Patched | SUSE-SU |
| Debian | Bullseye, Bookworm | ✅ Patched | DSA |
| CloudLinux | 8, 9 | ✅ Patched | Advisory |