
Proof-of-concept for CVE-2026-31431 demonstrating live process code injection via page cache, achieving arbitrary code execution in a running process without root.
Demonstrates arbitrary code execution in a running process via page cache.
by @secinfosex
What it does:
Success: check() returns the real PID — a syscall executed by the kernel in the process context. Arbitrary code execution confirmed.
Requirements:
Usage: python3 copy_fail_inject_poc.py