
CVE-2026-31431 - Guide de Remédiation et Mesures de Protection
This repository documents the CVE-2026-31431 vulnerability, nicknamed Copy Fail, and provides a defensive remediation procedure for potentially exposed Linux systems.
⚠️ This repository is strictly focused on defense, authorized auditing, hardening, and remediation.
It does not provide an exploitation procedure and must not be used to compromise third-party systems.
CVE-2026-31431 / Copy Fail is a local privilege escalation vulnerability in the Linux kernel.
It affects the kernel's cryptographic subsystem, more specifically the AF_ALG user interface and the algif_aead module. The flaw is related to an optimization introduced in 2017 in the Linux kernel's AEAD path. Under certain conditions, an unprivileged local user can trigger a controlled write into the page cache of a readable file, notably a setuid binary, which can lead to privilege escalation to root.
The vulnerability is rated High with a CVSS v3.1 score of 7.8.
| Element | Detail |
|---|---|
| CVE | CVE-2026-31431 |
| Public name | Copy Fail |
| Type | Local Privilege Escalation, LPE |
| Component | Linux kernel crypto subsystem |
| Affected module | algif_aead |
| Interface | AF_ALG |
| Mechanism involved | AEAD, authencesn, splice(), page cache |
| CVSS v3.1 score | 7.8 High |
| Privileges required | Unprivileged local account |
| User interaction | None |
| Impact | High confidentiality, integrity, and availability |
Public sources indicate that Linux distributions shipping a kernel derived from a vulnerable branch since the 2017 optimization may be exposed.
Examples of platforms mentioned in public publications:
| Distribution | Example of publicly tested kernel version |
|---|---|
| Ubuntu 24.04 LTS | 6.17.0-1007-aws |
| Amazon Linux 2023 | 6.18.8-9.213.amzn2023 |
| RHEL 10.1 | 6.12.0-124.45.1.el10_1 |
| SUSE 16 | 6.12.0-160000.9-default |
| Debian | Depending on kernel version and security status |
| AlmaLinux / Rocky Linux / Oracle Linux | Depending on kernel version and vendor backports |
The exact status depends on the kernel version, vendor, security backports, and already applied patches.
This vulnerability is particularly dangerous in environments where untrusted users or workloads have access to a local shell or a shared execution environment.
Environments to prioritize:
Main risk:
root;uname -a
uname -r
lsmod | grep algif_aead || true
sudo lsof -nP | grep AF_ALG || true
dpkg -l | grep -E '^ii\\s+linux-image|^ii\\s+linux-modules'
rpm -qa | grep -E '^kernel|^kernel-core'
rpm -qa | grep -E '^kernel'
Priority option: apply the vendor kernel patch The proper remediation is to install a patched kernel provided by the distribution, then reboot onto that kernel.
sudo apt update
sudo apt full-upgrade -y
sudo reboot
sudo dnf update -y kernel kernel-core kernel-modules
sudo reboot
sudo zypper refresh
sudo zypper patch
sudo reboot
# After reboot:
uname -r
If no patched kernel is yet available or if an immediate reboot is impossible, apply a temporary mitigation.
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif-aead.conf
sudo modprobe -r algif_aead 2>/dev/null || true
sudo rmmod algif_aead 2>/dev/null || true
sudo update-initramfs -u
sudo dracut -f
sudo mkinitrd
sudo reboot
sudo modprobe algif_aead
echo $?
On some kernels, the module may be compiled directly into the kernel and cannot be loaded/unloaded as a module.
grep CONFIG_CRYPTO_USER_API_AEAD /boot/config-$(uname -r)
CONFIG_CRYPTO_USER_API_AEAD=m
The component is a module. The mitigation via /etc/modprobe.d/ is applicable.
CONFIG_CRYPTO_USER_API_AEAD=y
The component is built into the kernel. The modprobe.d mitigation is not sufficient.
In this case, preferably use:
Some sources mention the following kernel option as a possible workaround:
initcall_blacklist=algif_aead_init
Must be tested outside production before general deployment. This option may vary depending on the kernel, distribution, and boot configuration.
For Docker, Podman, Kubernetes, and CI/CD, the ability for untrusted workloads to open AF_ALG sockets must be reduced.
sudo lsof -nP | grep AF_ALG || true
lsmod | grep algif_aead || true
find / -perm -4000 -type f 2>/dev/null
sudo ausearch -f /usr/bin/su 2>/dev/null || true
sudo auditctl -w /usr/bin/su -p x -k su_exec_monitoring
sudo ausearch -k su_exec_monitoring
last -a
lastlog
getent passwd
sudo find /etc/cron* -type f -ls 2>/dev/null
sudo find /root /home -name authorized_keys -type f -ls 2>/dev/null
sudo journalctl --since "48 hours ago"