
Proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability in the algif_aead module, enabling unprivileged users to gain root via a 4-byte write into page cache.
This repository contains a Proof of Concept exploit for CVE-2026-31431, a high-severity Linux kernel local privilege escalation vulnerability that allows any unprivileged local user to gain root access. The flaw, dubbed “Copy Fail”, resides in the algif_aead module and can be chained with the AF_ALG socket interface and the splice() system call to perform a controlled 4-byte write into the page cache of any readable file, such as the setuid binary /usr/bin/su.
The vulnerability affects nearly all Linux kernels released since 2017, including all major distributions (Ubuntu, Debian, RHEL, SUSE, Amazon Linux and many others). It was publicly disclosed on 29 April 2026. A fix has been committed upstream (commit a664bf3d603d), but many vendors are still in the process of releasing patched kernels. Until a fixed kernel is available, it is strongly advised to disable the algif_aead kernel module as a temporary mitigation.
⚠ Important: This material is provided strictly for educational and authorised security research purposes. Do not use it against systems you do not own or without explicit permission.
The repository contains two PoC implementations that demonstrate the exploitation from different angles.
copy-fail-poc-short.py — minimal, close to originalA condensed version that stays very close to the originally published Python exploit. It uses single-letter variable names and omits comments or constants, making it extremely compact (732 bytes). This variant:
/usr/bin/su and a raw AF_ALG AEAD socket.os.splice to zero-copy the corresponding 4-byte chunk from the target file./usr/bin/su to drop into a root shell.copy-fail-poc.py — fully refactored, comprehensiveA completely rewritten, well-documented version that follows Python best practices. This variant:
send_data_over_crypto_socket()) to isolate the core logic.This version is ideal for those who want to understand the vulnerability in depth or adapt the code for further research.
At a high level, the exploit:
setuid binary (/usr/bin/su).AF_ALG AEAD socket and configures it with the parameters required to trigger the logic flaw.splice() mechanism.algif_aead module, the kernel erroneously writes 4 bytes of attacker-controlled data into the page cache of the target binary./usr/bin/su effectively patches the binary at runtime, allowing an unprivileged user to execute a patched version that returns a root shell.The exploit is extremely reliable (100% success rate) and does not require any race windows or per-kernel offsets.
a664bf3d603d (git.kernel.org)