Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/sebastian294/cve-2026-31431
Privilege EscalationVulnerability AnalysisExploitationLearning & EducationBinary ExploitationLabs & Practice
GitHubsebastian294/cve-2026-31431

cve-2026-31431

Analísis - POC - Mitigación

View Repository
14 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431 — Copy Fail: Linux Kernel LPE Research Lab

Educational purposes only. Do NOT use on systems without explicit authorization.


Index

  • Description of the vulnerability
  • Affected components
  • How it works
  • Lab setup (Docker)
  • PoC — Demonstration
  • Mitigation
  • References

Vulnerability Description

FieldValue
CVECVE-2026-31431
AliasCopy Fail
CVSS7.8 (High)
TypeLocal Privilege Escalation (LPE)
Affected Kernel2017 – 2026 (commit 72548b093ee3 onward)
Upstream Fixcommit a664bf3d603d (revert of 2017)
DisclosureApril 29, 2026 (Theori / Xint Code)

Copy Fail is a deterministic logic bug (no race conditions required) in the cryptographic subsystem of the Linux kernel. It allows an unprivileged user to write 4 controlled bytes into the page cache of any readable file on the system, including setuid binaries like su or sudo.

Why is it especially critical?

Compared to similar previous vulnerabilities:

VulnerabilityTypeRace required?Portable?Exploit size
Dirty Cow (CVE-2016-5195)CoW raceYesPartial~KB
Dirty Pipe (CVE-2022-0847)pipe bufferNoLimited~KB
Copy Fail (CVE-2026-31431)LogicNoTotal732 bytes

Affected Components

Linux kernel — crypto/authencesn.c
  └── algif_aead (AF_ALG module)
        └── in-place optimization (commit 72548b093ee3, 2017)
              └── AEAD scratch write → crosses scatterlist boundary
                    └── writes 4 bytes into page cache of external file

Affected distributions: Ubuntu, Debian, RHEL, Amazon Linux, SUSE, Fedora, Arch, AlmaLinux — any distro with kernel ≥ 2017.


How It Works

Root cause

In 2017, an optimization was introduced that makes req->src and req->dst point to the same combined scatterlist. This causes the page cache pages (coming from splice()) to be chained directly into the writable destination scatterlist.

Exploitation chain

1. Open AF_ALG socket with authencesn algorithm
2. Use splice() to feed page cache pages of the target binary
   into the AF_ALG socket (e.g., /usr/bin/sudo)
3. Execute AEAD decryption operation
4. authencesn uses the destination buffer as scratch pad →
   writes seqno_hi (4 controlled bytes) OUTSIDE the legitimate output,
   crossing the scatterlist boundary
5. The 4 bytes land in the page cache page of the target binary
6. The file on disk does NOT change → integrity checks detect nothing
7. The modified binary in memory executes payload → root

Why it is stealthy

The write bypasses the normal VFS write path. The file on disk remains intact. Tools like sha256sum, aide, tripwire, or inotify do not detect the change because they operate on the file on disk or on the inode, not on the page cache in memory.


Lab Setup (Docker)

The lab uses a vulnerable kernel to demonstrate page cache corruption. In Docker environments, full privilege escalation depends on the host configuration (shared kernel).

# Clone the repo

cd cve-2026-31431

# Build the vulnerable image
docker build -t copyfail-lab -f docker/Dockerfile.vulnerable .

# Run the lab
docker run --rm -it \
  --cap-add=NET_ADMIN \
  --security-opt seccomp=unconfined \
  copyfail-lab bash

# Inside the container:
cd /lab
python3 exploit/poc.py

Requirements

  • Docker ≥ 20.x
  • Host kernel: Ubuntu/Debian with unpatched kernel 5.x or 6.x (see table in docs/)
  • Python 3.10+ in the container (for os.splice)

PoC — Demonstration

See exploit/poc.py and exploit/README.md.

The PoC demonstrates:

  1. Page cache corruption (verifiable)
  2. Writing 4 controlled bytes into target file
  3. Full LPE: depends on host kernel (see notes)

Mitigation

See mitigation/README.md for detailed instructions.

TL;DR — Immediate mitigation (no reboot):

# Disable the affected module
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf
sudo modprobe -r algif_aead 2>/dev/null || true

Permanent fix: Update the kernel to a patched version (post a664bf3d603d).


Repository Structure

cve-2026-31431/
├── README.md                    ← this file
├── docs/
│   ├── technical-analysis.md    ← in-depth technical analysis
│   └── affected-kernels.md      ← table of affected/patched kernels
├── exploit/
│   ├── README.md                ← PoC documentation
│   └── poc.py                   ← proof of concept (Python 3.10+)
├── mitigation/
│   ├── README.md                ← mitigation guide
│   ├── disable-algif.conf       ← modprobe config
│   └── check-vulnerable.sh      ← detection script
├── docker/
│   ├── Dockerfile.vulnerable    ← vulnerable lab
│   └── Dockerfile.patched       ← lab with mitigation applied
└── scripts/
    └── setup-lab.sh             ← lab automation

Disclosure Timeline

DateEvent
2017Commit 72548b093ee3 introduces the bug in the kernel
~2025Theori/Xint Code begins analysis of the crypto subsystem
Apr 28, 2026Coordination with distributors
Apr 29, 2026Public disclosure + PoC published
May 1, 2026Patched kernels available in production repositories
May 1, 2026Added to CISA KEV catalog

References

  • Xint Code — Copy Fail official writeup
  • copy.fail — advisory site
  • Official GitHub — theori-io/copy-fail-CVE-2026-31431
  • NVD — CVE-2026-31431
  • Ubuntu Security Advisory
  • Microsoft Security Blog
  • Unit 42 — Palo Alto Analysis
  • Upstream fix commit a664bf3d603d

Download Tool