Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31431 — Proof-of-concept exploit for CVE-2026-31431, a Linux local privilege escalation via authencesn logic bug, with ARM64 variant for authorized lab validation. | Kitploit
Tools/GitHubGitHub/pascal-gujer/cve-2026-31431
Privilege EscalationExploit FrameworksVulnerability AnalysisExploitationBinary Exploitation
GitHubpascal-gujer/cve-2026-31431

CVE-2026-31431

Proof-of-concept exploit for CVE-2026-31431, a Linux local privilege escalation via authencesn logic bug, with ARM64 variant for authorized lab validation.

View Repository
21135 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431: Copy Fail PoC + ARM64 Validation

Copy Fail is a Linux local privilege escalation published by Theori/Xint as CVE-2026-31431. The project page describes a logic bug in authencesn that can be reached through AF_ALG and splice(), producing a small page-cache write against a setuid binary. On affected systems, an unprivileged local user can become root.

This repository keeps a copy of the upstream proof of concept and adds an ARM64 variant tested on Ubuntu 25.10 ARM.

ARM64 validation on Ubuntu 25.10 ARM

Contents

FilePurpose
copy_fail_exp.pyOriginal upstream PoC, with its source URL noted in the file header.
copy_fail_exp_arm64.pyARM64-adapted PoC, tested and working on Ubuntu 25.10 ARM.

What These Tools Test

These scripts are for authorized validation in disposable lab systems only. They are not general vulnerability scanners. They attempt the Copy Fail exploitation path against /usr/bin/su; if the host is vulnerable and the environment is compatible, the result is a real root shell.

⚡ Use the original PoC to validate the public exploit path on compatible Linux systems. Use the ARM64 variant to test ARM-based Linux hosts where the embedded payload differs from the upstream script.

A failed run does not prove a host is patched. Kernel version, distribution backports, architecture, local hardening, container policy, and runtime environment can all affect behavior.

Patch And Mitigation

Patch first. According to copy.fail, systems should update to a distribution kernel that includes mainline commit a664bf3d603d, then reboot into that kernel and verify the running version.

Until the kernel can be patched, disable the algif_aead module:

sudo sh -c 'printf "%s\n" "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf'
sudo rmmod algif_aead 2>/dev/null || true

For untrusted workloads such as containers, CI runners, sandboxes, and shared developer hosts, also block AF_ALG socket creation with seccomp policy.

The mitigation guidance from copy.fail notes that disabling algif_aead should not affect typical dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL/GnuTLS/NSS, SSH, or kernel keyring crypto use. It may affect software explicitly configured to use AF_ALG sockets.

References

  • Copy Fail project page
  • Upstream PoC repository
  • Upstream raw PoC used here
Download Tool