
Proof-of-concept exploit for Linux kernel CVE-2026-31431, leveraging AF_ALG sockets to escalate privileges to root via payload injection and shell spawning.
🧬 modrosnlr5 – Linux Kernel LPE PoC (CVE-2026-31431)
Proof-of-concept tool designed to validate the exploitation of the CVE-2026-31431 vulnerability on Linux systems.
The exploit leverages the kernel's AF_ALG socket interface to inject a payload and obtain a root shell from an unprivileged user session.
⚖️ Ethical and controlled use: This code is distributed exclusively for research, training, and authorized auditing purposes. It should only be run in environments where you have explicit permission.
sudo, wheel, and root groups.su binary via os.splice and decompression through zlib.ESC), adding a safety layer before the actual payload deployment.zlib and injected into the target process's space by manipulating the socket's data flow./usr/bin/su.python3 mod_rosnlr5.py
📘 Credits Original research and base PoC: copy.fail
Adaptation, automation, and repository development: ROSNLR5
modrosnlr5 – fundamentals of local escalation over AF_ALG