Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
copy-fail-CVE-2026-31431-poc — Proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability in the algif_aead module, enabling unprivileged users to gain root via a 4-byte write into page cache. | Kitploit
Tools/GitHubGitHub/euriconicacio/copy-fail-cve-2026-31431-poc
Privilege EscalationExploit FrameworksVulnerability AnalysisExploitationBinary Exploitation
GitHubeuriconicacio/copy-fail-cve-2026-31431-poc

copy-fail-CVE-2026-31431-poc

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability in the algif_aead module, enabling unprivileged users to gain root via a 4-byte write into page cache.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
1275 months agoNot yet reviewed

CVE-2026-31431 — Copy Fail Proof of Concept

This repository contains a Proof of Concept exploit for CVE-2026-31431, a high-severity Linux kernel local privilege escalation vulnerability that allows any unprivileged local user to gain root access. The flaw, dubbed “Copy Fail”, resides in the algif_aead module and can be chained with the AF_ALG socket interface and the splice() system call to perform a controlled 4-byte write into the page cache of any readable file, such as the setuid binary /usr/bin/su.

The vulnerability affects nearly all Linux kernels released since 2017, including all major distributions (Ubuntu, Debian, RHEL, SUSE, Amazon Linux and many others). It was publicly disclosed on 29 April 2026. A fix has been committed upstream (commit a664bf3d603d), but many vendors are still in the process of releasing patched kernels. Until a fixed kernel is available, it is strongly advised to disable the algif_aead kernel module as a temporary mitigation.

⚠ Important: This material is provided strictly for educational and authorised security research purposes. Do not use it against systems you do not own or without explicit permission.

Proof-of-Concept Files

The repository contains two PoC implementations that demonstrate the exploitation from different angles.

1. copy-fail-poc-short.py — minimal, close to original

A condensed version that stays very close to the originally published Python exploit. It uses single-letter variable names and omits comments or constants, making it extremely compact (732 bytes). This variant:

  • Opens /usr/bin/su and a raw AF_ALG AEAD socket.
  • Sends a decompressed payload in 4-byte chunks through the socket.
  • Uses os.splice to zero-copy the corresponding 4-byte chunk from the target file.
  • Finally executes /usr/bin/su to drop into a root shell.

2. copy-fail-poc.py — fully refactored, comprehensive

A completely rewritten, well-documented version that follows Python best practices. This variant:

  • Defines meaningful constants and helper functions.
  • Includes detailed comments explaining each step of the attack chain.
  • Uses a dedicated function (send_data_over_crypto_socket()) to isolate the core logic.
  • Adds proper error handling and removes all magic numbers.

This version is ideal for those who want to understand the vulnerability in depth or adapt the code for further research.

What the Exploit Does

At a high level, the exploit:

  1. Opens the target setuid binary (/usr/bin/su).
  2. Creates an AF_ALG AEAD socket and configures it with the parameters required to trigger the logic flaw.
  3. Splices data from the open file descriptor into the socket, taking advantage of the zero-copy splice() mechanism.
  4. Because of the flaw in the algif_aead module, the kernel erroneously writes 4 bytes of attacker-controlled data into the page cache of the target binary.
  5. Modifying the in-memory page cache of /usr/bin/su effectively patches the binary at runtime, allowing an unprivileged user to execute a patched version that returns a root shell.

The exploit is extremely reliable (100% success rate) and does not require any race windows or per-kernel offsets.

References

  • CVE entry: CVE-2026-31431
  • Official disclosure site: copy.fail
  • Xint Code technical write-up: Copy Fail – Linux Local Privilege Escalation
  • Wiz blog analysis: Copy.Fail: Universal Linux LPE Vulnerability
  • Linux kernel mainline fix: a664bf3d603d (git.kernel.org)
  • CERT-EU advisory (2026-005): High Vulnerability in the Linux Kernel (“Copy Fail”)
Download Tool