
Local privilege escalation exploit for CVE-2026-31431, a Linux kernel AF_ALG + splice page-cache overwrite. Includes PoC, BPFtrace detection script, and QEMU test environment for authorized security research.
Linux kernel local privilege escalation via AF_ALG + splice page-cache overwrite
For authorized security research, penetration testing, and educational purposes only. Do not use against systems you do not own or have explicit written permission to test.
CVE-2026-31431 is a local privilege escalation (LPE) vulnerability in the Linux kernel. An
unprivileged local user can gain root access by combining the AF_ALG socket interface with
splice() to perform an authenticated write directly into a page-cache page belonging to a
setuid binary.
The exploit overwrites the su binary in the page cache without modifying the on-disk inode,
bypassing integrity mechanisms that rely solely on file metadata or block-level checksums.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-31431 |
| Type | Local Privilege Escalation (LPE) |
| CVSS v3.1 Score | 7.8 High — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (source: kernel.org) |
| Kernel subsystems | crypto/af_alg.c, mm/splice.c |
| Attack vector | Local — unprivileged user account required |
| Root cause | algif_aead accepts sendfile() over an AEAD socket without enforcing copy-on-write semantics on the mapped page-cache page prior to splice() completing the transfer |
| Distro | Kernel version | Arch |
|---|---|---|
| Ubuntu 24.04 LTS | 6.17.0-1007-aws | x86_64 |
| Amazon Linux 2023 | 6.18.8-9.213.amzn2023 | x86_64 |
| RHEL 10.1 | 6.12.0-124.45.1.el10_1 | x86_64 |
| SUSE 16 | 6.12.0-160000.9-default | x86_64 |
| Raspberry Pi OS (Pi 5) | 6.12.75+rpt-rpi-2712 | aarch64 |
.
├── exploit.py # PoC — page-cache overwrite and privilege escalation
├── detect.bt # BPFtrace script for real-time detection
├── run-vm.sh # QEMU test environment automation (optional)
├── PAYLOAD.md # Payload encoding analysis (hex → zlib → ELF → shellcode)
└── LICENSE
Run exploit.py as an unprivileged local user on any vulnerable system — no sudo needed:
python3 exploit.py
The script performs the following steps:
AF_ALG (algif_aead) and locates the su binary.su binary as a raw file descriptor and overwrites its page-cache pages via
AF_ALG + sendfile.Supported architectures:
| Architecture | Variants |
|---|---|
| x86_64 | — |
| aarch64 | — |
| riscv64 | — |
| ppc64le | — |
| arm | armv5l, armv6l, armv7l |
| x86 32-bit | i386, i486, i586, i686 |
| MIPS 64-bit | mips64, mips64el |
| LoongArch | loong64, loongarch64 |
| s390x | — |
Monitor for exploitation attempts in real time with detect.bt. Requires root:
sudo bpftrace detect.bt
# or
doas bpftrace detect.bt
The script tracks three indicators per PID using a bitmask in @suspect[pid]:
| Bit | Syscall | Indicator |
|---|---|---|
0x1 | socket(AF_ALG, SOCK_SEQPACKET) | AF_ALG socket created |
0x2 | setsockopt(SOL_ALG, ...) | Crypto operation configured |
0x4 | sendmsg(MSG_MORE) + splice() | Page-cache overwrite attempted |
An alert fires when all three bits are set (@suspect[pid] == 0x7) on the same PID.
exploit.pyAF_ALG/algif_aead module loadeddetect.btbpftrace ≥ 0.12# Ubuntu/Debian
sudo apt install bpftrace
# RHEL/CentOS/Fedora
sudo dnf install bpftrace
# Amazon Linux
sudo yum install bpftrace
# SUSE
sudo zypper install bpftrace
# Alpine
sudo apk add bpftrace
Update your distribution's kernel package to one that includes mainline commit
a664bf3d603d,
which reverts the 2017 algif_aead in-place optimization so that page-cache pages can no
longer end up in the writable destination scatterlist. Most major distributions are shipping
the fix now.
algif_aead (while waiting for a patch)blacklist can be bypassed with an explicit modprobe algif_aead. The install .../bin/false
directive overrides the install command entirely, making every load attempt fail:
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf
sudo rmmod algif_aead 2>/dev/null || true
| Affected? | Subsystem/Use case |
|---|---|
| No | dm-crypt/LUKS, kTLS, IPsec/XFRM, in-kernel TLS |
| No | OpenSSL, GnuTLS, NSS default builds |
| No | SSH, kernel keyring crypto |
| Maybe | OpenSSL with the afalg engine explicitly enabled |
| Maybe | Embedded crypto offload paths or apps that bind aead/skcipher/hash sockets directly |