Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31431-CopyFail — Proof-of-concept exploit for CVE-2026-31431 (Copy Fail), a Linux kernel LPE via algif_aead page-cache corruption, with detection, lab, and mitigation guidance. | Kitploit
Tools/GitHubGitHub/0xfuffm3/cve-2026-31431-copyfail
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingLearning & EducationContainer EscapeBinary ExploitationLabs & Practice

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
0xfuffm3/cve-2026-31431-copyfail

CVE-2026-31431-CopyFail

Proof-of-concept exploit for CVE-2026-31431 (Copy Fail), a Linux kernel LPE via algif_aead page-cache corruption, with detection, lab, and mitigation guidance.

View Repository
234 months agoNot yet reviewed
                     ██████╗ ██████╗ ██████╗ ██╗   ██╗    ███████╗ █████╗ ██╗██╗
                    ██╔════╝██╔═══██╗██╔══██╗╚██╗ ██╔╝    ██╔════╝██╔══██╗██║██║
                    ██║     ██║   ██║██████╔╝ ╚████╔╝     █████╗  ███████║██║██║
                    ██║     ██║   ██║██╔═══╝   ╚██╔╝      ██╔══╝  ██╔══██║██║██║
                         ╚██████╗╚██████╔╝██║        ██║       ██║     ██║  ██║██║███████╗
                          ╚═════╝ ╚═════╝ ╚═╝        ╚═╝       ╚═╝     ╚═╝  ╚═╝╚═╝╚══════╝

CVE-2026-31431 — "Copy Fail"

Linux Kernel Local Privilege Escalation via algif_aead Page Cache Corruption


CVE CVSS Kernel License Status


⚠️ AUTHORIZED USE ONLY — This repository is strictly for penetration testers, security researchers, and defenders operating under lawful authorization. Misuse is a criminal offense.


📖 Table of Contents

#SectionDescription
1What is Copy Fail?Vulnerability summary
2Technical Deep DiveRoot cause analysis
3Affected SystemsDistro & kernel matrix
4Repository StructureFile layout
5Lab SetupReproduce safely
6Exploit UsagePentest workflow
7DetectionYARA, Sigma, scripts
8MitigationPatch & hardening
9Pentest ReportingReport templates
10Legal & EthicsDisclaimer
11ReferencesCVEs, advisories, blogs

🔍 What is Copy Fail?

Copy Fail is a local privilege escalation (LPE) vulnerability disclosed on April 29, 2026, affecting virtually every major Linux distribution running kernels since 2017.

Unprivileged User  ──►  AF_ALG + splice()  ──►  4-byte Page Cache Write  ──►  ROOT

Key Facts at a Glance

PropertyDetail
CVE IDCVE-2026-31431
NicknameCopy Fail
CVSS v3.17.8 (HIGH)
Attack VectorLocal
Privileges RequiredLow (any unprivileged user)
User InteractionNone
DiscovererXint Code (Theori)
DisclosedApril 29, 2026
Exploit Size732 bytes (Python PoC)
Patch Status✅ Available — revert commit a664bf3d603d

Why This Is Dangerous

  • 🕵️ Stealthy — Modification lives only in the page cache; the file on disk is never changed. Standard disk forensics will not detect it.
  • ⚡ Reliable — Deterministic logic flaw, not a race condition. Exploitation is consistent across environments.
  • 🌐 Universal — Affects Ubuntu, RHEL, Amazon Linux, SUSE, Debian — every major distro since 2017.
  • ☸️ Cloud/K8s Impact — Can facilitate container escape in Kubernetes workloads and CI/CD runners.
  • 🤖 AI-Discovered — Found by Xint Code's AI system with ~1 hour of scan time and a single operator prompt.

🔬 Technical Deep Dive

Root Cause

The vulnerability stems from a buggy in-place optimization introduced in 2017 (commit 72548b093ee3) inside the algif_aead module of the Linux kernel's userspace crypto API (AF_ALG).

AF_ALG (userspace crypto API)
└── algif_aead module
    └── authencesn template  ◄── VULNERABLE
        └── in-place optimization (2017)
            └── req->src == req->dst  ◄── pages from splice() chained into writable dst scatterlist

Attack Flow

Step 1: Open AF_ALG AEAD socket
        socket(AF_ALG, SOCK_SEQPACKET, 0)

Step 2: Send splice() pages referencing target file
        (page cache pages of a privileged binary, e.g. /usr/bin/sudo)

Step 3: Trigger authencesn scratch write
        authencesn uses dst buffer as scratch pad →
        writes 4 controlled bytes PAST the legitimate output region

Step 4: Page cache entry for the target file is now corrupted
        (disk file untouched — only in-memory copy modified)

Step 5: Execute the modified binary → ROOT

Why the Page Cache?

The Linux kernel's page cache backs in-memory copies of files. When a file is read, its pages are cached. The splice() syscall can reference these cached pages directly. By feeding page cache pages into the AF_ALG AEAD scatterlist, the authencesn scratch write lands inside those cached pages, effectively patching the in-memory copy of any readable file — including privileged binaries like sudo, pkexec, or passwd.

The Fix

The upstream fix reverts the flawed 2017 optimization:

# Fixed in commit: a664bf3d603d
git show a664bf3d603d

🖥️ Affected Systems

Linux Kernel Versions

Kernel BranchAffected?Fixed Version
4.9.x (LTS)✅ Yes4.9.340+
5.4.x (LTS)✅ Yes5.4.295+
5.10.x (LTS)✅ Yes5.10.239+
5.15.x (LTS)✅ Yes5.15.185+
6.1.x (LTS)✅ Yes6.1.132+
6.6.x (LTS)✅ Yes6.6.83+
6.12.x (LTS)✅ Yes6.12.19+
< 4.9 (pre-2017)❌ NoN/A — optimization not present

Distribution Matrix

DistributionAffected VersionsPatched?Advisory
Ubuntu< 26.04 (all releases)✅ PatchedUSN
Ubuntu 26.04 (Resolute)❌ Not affected——
RHEL / CentOS7, 8, 9✅ PatchedRHSA-2026
Amazon Linux2, 2023✅ PatchedALAS
SUSE / openSUSEAll affected✅ PatchedSUSE-SU
DebianBullseye, Bookworm✅ PatchedDSA
CloudLinux8, 9✅ PatchedAdvisory

📁 Repository Structure

Download Tool