Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Linux-Kernel-Copy-Fail-CVE-2026-31431- — Analysis and mitigation of Linux kernel Copy Fail (CVE-2026-31431) vulnerability exploiting AF_ALG/splice page cache mutation, with PoC checker, auditd detection rules, and kernel update verification. | Kitploit
Tools/GitHubGitHub/jihwan77/linux-kernel-copy-fail-cve-2026-31431-
Vulnerability AnalysisExploitationBinary AnalysisLearning & EducationIncident Response
GitHubjihwan77/linux-kernel-copy-fail-cve-2026-31431-

Linux-Kernel-Copy-Fail-CVE-2026-31431-

Analysis and mitigation of Linux kernel Copy Fail (CVE-2026-31431) vulnerability exploiting AF_ALG/splice page cache mutation, with PoC checker, auditd detection rules, and kernel update verification.

View Repository
102 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Copy Fail (CVE-2026-31431) Vulnerability Analysis and Response Practice

This project analyzes the operational principle of the Linux Kernel Copy Fail (CVE-2026-31431) vulnerability and compares the pre-patch and post-patch state using the non-destructive checker from the public PoC repository.
It does not perform actual setuid binary modification or /etc/passwd modification exploits, but focuses on safely checking vulnerability based on a temporary testfile and analyzing detection/mitigation perspectives.


1. Project Goals

The goal of this project is not simply to run an exploit, but to understand the combination of internal structures that cause a Linux kernel vulnerability and to organize how to identify and respond from an operational perspective.

The scope of work is as follows:

Vulnerability principle analysis
    ↓
PoC code structure analysis
    ↓
Non-destructive checker-based practice
    ↓
Pre-patch vs. post-patch comparison
    ↓
Detection/mitigation measures summary

In this practice, only vulnerable.c from the copy-fail-c repository was executed.


2. Practice Environment

CategoryPre-patchPost-patch
OSUbuntu 24.04.2 LTSUbuntu 24.04.4 LTS
Kernel6.8.0-53-generic6.8.0-134-generic
AccountNormal user clientNormal user client
checkervulnerablevulnerable
Test methodNon-destructive check based on temporary testfileSame checker re-executed

Pre-patch kernel info:

Linux ubuntu-server 6.8.0-53-generic #55-Ubuntu SMP PREEMPT_DYNAMIC Fri Jan 17 15:37:52 UTC 2025 x86_64 x86_64 x86_64 GNU/Linux

Post-patch kernel info:

Linux ubuntu-server 6.8.0-134-generic #134-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 26 18:43:11 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux

Kernel package change summary:

- linux-image-6.8.0-53-generic  6.8.0-53.55
- linux-image-generic           6.8.0-53.55+1

+ linux-image-6.8.0-134-generic 6.8.0-134.134
+ linux-image-generic           6.8.0-134.134
+ linux-generic                 6.8.0-134.134
+ linux-headers-generic         6.8.0-134.134

3. Vulnerability Concept Summary

Copy Fail is a vulnerability that occurs when the Linux kernel's AF_ALG AEAD processing path and splice() zero-copy behavior combine, causing the page cache of a read-only file to be used as an incorrect write target.

The core components are as follows:

ElementRole
Linux page cacheKernel mechanism that caches disk file contents in RAM
splice()A zero-copy syscall that connects data via references within the kernel without copying to user space
AF_ALGAn interface that allows user space to use the Linux kernel crypto API like a socket
AEAD in-place processingOptimization that processes input and output in the same buffer instead of separate buffers
authencesnCrypto template that generates a 4-byte scratch write during AEAD processing

The core flow of the vulnerability is as follows:

Readable file
    ↓
Loaded into Linux page cache
    ↓
Page cache reference passed to AF_ALG crypto path via splice()
    ↓
Input and output scatterlists become entangled due to AEAD in-place processing
    ↓
4-byte scratch write occurs during authencesn processing
    ↓
Write occurs not to a separate output buffer but to the page cache
    ↓
Page cache mutation occurs

In other words, splice() passes a page cache reference, AEAD in-place processing ties input and output through the same path, and authencesn causes the actual 4-byte write.


4. PoC Code Structure Analysis

The repository structure used in the practice is as follows:

copy-fail-c/
├── exploit.c
├── exploit-passwd.c
├── vulnerable.c
├── payload.c
├── utils.c
├── utils.h
├── Makefile
└── nolibc/
FileRoleUsage in this practice
utils.c, utils.hImplementation of AF_ALG/splice based page cache mutation primitiveUsed for analysis and executing vulnerable
vulnerable.cNon-destructive vulnerability check tool based on temporary testfileExecuted
exploit.csetuid root binary page cache modification variantNot executed
exploit-passwd.c/etc/passwd page cache modification variantNot executed
payload.cPayload to be executed with root privilegesNot executed
MakefileBuild automationOnly vulnerable target used
nolibc/Lightweight libc replacement for building small static ELF payloadsOnly analyzed

4.1 utils.c

The core of utils.c is the patch_chunk() family of page cache mutation primitives. This function uses AF_ALG and splice() to connect the page cache of the target file to the crypto processing path, and on vulnerable kernels checks whether part of the page cache gets overwritten during AEAD processing.

4.2 vulnerable.c

vulnerable.c does not touch actual system files. It creates a temporary testfile in the current directory and checks whether its page cache is mutated.

In this project, only this file was executed.


5. Practice Procedure

5.1 Record Pre-patch State

Before performing the kernel update, the OS, kernel, and package states were recorded.

mkdir -p ~/copyfail-mini/{before,after,logs}
cd ~/copyfail-mini

uname -a | tee before/uname.txt
cat /etc/os-release | tee before/os-release.txt
dpkg -l | grep -E 'linux-image|linux-headers|linux-generic|linux-virtual' | tee before/kernel-package.txt

5.2 Clone PoC Repository and Build Checker

git clone https://github.com/jihwan77/copy-fail-c.git
cd copy-fail-c

make clean
make vulnerable

In this practice, the default make was not used to build exploit binaries together; only the vulnerable target was used.

5.3 Run Pre-patch Checker

./vulnerable > ../before/vulnerable-output.txt 2>&1
echo $? >> ../before/vulnerable-output.txt
cat ../before/vulnerable-output.txt

Pre-patch execution result:

alt text

Judgment:

exit code 100
→ page cache mutation confirmed
→ Copy Fail primitive confirmed in pre-patch kernel

6. Pre-patch vs Post-patch Comparison

6.1 Kernel Update

After saving the pre-patch results, Ubuntu package update was performed.

sudo apt update
sudo apt full-upgrade -y
sudo reboot

After reboot, the kernel changed as follows:

Before: 6.8.0-53-generic
After : 6.8.0-134-generic

6.2 Run Post-patch Checker

cd ~/copyfail-mini/copy-fail-c
make clean
make vulnerable

./vulnerable > ../after/vulnerable-output.txt 2>&1
echo "exit_code=$?" >> ../after/vulnerable-output.txt
cat ../after/vulnerable-output.txt

Post-patch execution result:

alt text

Result comparison:

ItemPre-patchPost-patch
Kernel6.8.0-53-generic6.8.0-134-generic
Checker resultVULNERABLEauthencesn template not registered
Exit Code1002
Page cache mutationConfirmedChecker did not reach mutation step
InterpretationCopy Fail primitive workingPoC required AEAD/authencesn path entry failed

7. Post-patch Result Interpretation

The post-patch exit_code=2 does not simply mean “not vulnerable.” Precisely, it means:

The authencesn(hmac(sha256),cbc(aes)) template of AF_ALG is not registered,
so the checker could not directly determine vulnerability.

Upon further checking, the algif_aead module load was blocked after the Ubuntu update.

lsmod | grep -E 'af_alg|algif_aead'

Result:

af_alg 32768 0

algif_aead was not loaded.

sudo modprobe algif_aead

Result:

Download Tool