
Proof-of-concept exploit for CVE-2026-31431, a Linux local privilege escalation via authencesn logic bug, with ARM64 variant for authorized lab validation.
Copy Fail is a Linux local privilege escalation published by Theori/Xint as
CVE-2026-31431. The project page describes a logic bug in
authencesn that can be reached through AF_ALG and splice(), producing a
small page-cache write against a setuid binary. On affected systems, an
unprivileged local user can become root.
This repository keeps a copy of the upstream proof of concept and adds an ARM64 variant tested on Ubuntu 25.10 ARM.

| File | Purpose |
|---|---|
copy_fail_exp.py | Original upstream PoC, with its source URL noted in the file header. |
copy_fail_exp_arm64.py | ARM64-adapted PoC, tested and working on Ubuntu 25.10 ARM. |
These scripts are for authorized validation in disposable lab systems only. They
are not general vulnerability scanners. They attempt the Copy Fail exploitation
path against /usr/bin/su; if the host is vulnerable and the environment is
compatible, the result is a real root shell.
⚡ Use the original PoC to validate the public exploit path on compatible Linux systems. Use the ARM64 variant to test ARM-based Linux hosts where the embedded payload differs from the upstream script.
A failed run does not prove a host is patched. Kernel version, distribution backports, architecture, local hardening, container policy, and runtime environment can all affect behavior.
Patch first. According to copy.fail, systems should update
to a distribution kernel that includes mainline commit a664bf3d603d, then
reboot into that kernel and verify the running version.
Until the kernel can be patched, disable the algif_aead module:
sudo sh -c 'printf "%s\n" "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf'
sudo rmmod algif_aead 2>/dev/null || true
For untrusted workloads such as containers, CI runners, sandboxes, and shared
developer hosts, also block AF_ALG socket creation with seccomp policy.
The mitigation guidance from copy.fail notes that disabling algif_aead should
not affect typical dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL/GnuTLS/NSS, SSH, or
kernel keyring crypto use. It may affect software explicitly configured to use
AF_ALG sockets.