
Analísis - POC - Mitigación
Educational purposes only. Do NOT use on systems without explicit authorization.
| Field | Value |
|---|---|
| CVE | CVE-2026-31431 |
| Alias | Copy Fail |
| CVSS | 7.8 (High) |
| Type | Local Privilege Escalation (LPE) |
| Affected Kernel | 2017 – 2026 (commit 72548b093ee3 onward) |
| Upstream Fix | commit a664bf3d603d (revert of 2017) |
| Disclosure | April 29, 2026 (Theori / Xint Code) |
Copy Fail is a deterministic logic bug (no race conditions required) in the cryptographic subsystem of the Linux kernel. It allows an unprivileged user to write 4 controlled bytes into the page cache of any readable file on the system, including setuid binaries like su or sudo.
Compared to similar previous vulnerabilities:
| Vulnerability | Type | Race required? | Portable? | Exploit size |
|---|---|---|---|---|
| Dirty Cow (CVE-2016-5195) | CoW race | Yes | Partial | ~KB |
| Dirty Pipe (CVE-2022-0847) | pipe buffer | No | Limited | ~KB |
| Copy Fail (CVE-2026-31431) | Logic | No | Total | 732 bytes |
Linux kernel — crypto/authencesn.c
└── algif_aead (AF_ALG module)
└── in-place optimization (commit 72548b093ee3, 2017)
└── AEAD scratch write → crosses scatterlist boundary
└── writes 4 bytes into page cache of external file
Affected distributions: Ubuntu, Debian, RHEL, Amazon Linux, SUSE, Fedora, Arch, AlmaLinux — any distro with kernel ≥ 2017.
In 2017, an optimization was introduced that makes req->src and req->dst point to the same combined scatterlist. This causes the page cache pages (coming from splice()) to be chained directly into the writable destination scatterlist.
1. Open AF_ALG socket with authencesn algorithm
2. Use splice() to feed page cache pages of the target binary
into the AF_ALG socket (e.g., /usr/bin/sudo)
3. Execute AEAD decryption operation
4. authencesn uses the destination buffer as scratch pad →
writes seqno_hi (4 controlled bytes) OUTSIDE the legitimate output,
crossing the scatterlist boundary
5. The 4 bytes land in the page cache page of the target binary
6. The file on disk does NOT change → integrity checks detect nothing
7. The modified binary in memory executes payload → root
The write bypasses the normal VFS write path. The file on disk remains intact. Tools like sha256sum, aide, tripwire, or inotify do not detect the change because they operate on the file on disk or on the inode, not on the page cache in memory.
The lab uses a vulnerable kernel to demonstrate page cache corruption. In Docker environments, full privilege escalation depends on the host configuration (shared kernel).
# Clone the repo
cd cve-2026-31431
# Build the vulnerable image
docker build -t copyfail-lab -f docker/Dockerfile.vulnerable .
# Run the lab
docker run --rm -it \
--cap-add=NET_ADMIN \
--security-opt seccomp=unconfined \
copyfail-lab bash
# Inside the container:
cd /lab
python3 exploit/poc.py
os.splice)See exploit/poc.py and exploit/README.md.
The PoC demonstrates:
See mitigation/README.md for detailed instructions.
TL;DR — Immediate mitigation (no reboot):
# Disable the affected module
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf
sudo modprobe -r algif_aead 2>/dev/null || true
Permanent fix: Update the kernel to a patched version (post a664bf3d603d).
cve-2026-31431/
├── README.md ← this file
├── docs/
│ ├── technical-analysis.md ← in-depth technical analysis
│ └── affected-kernels.md ← table of affected/patched kernels
├── exploit/
│ ├── README.md ← PoC documentation
│ └── poc.py ← proof of concept (Python 3.10+)
├── mitigation/
│ ├── README.md ← mitigation guide
│ ├── disable-algif.conf ← modprobe config
│ └── check-vulnerable.sh ← detection script
├── docker/
│ ├── Dockerfile.vulnerable ← vulnerable lab
│ └── Dockerfile.patched ← lab with mitigation applied
└── scripts/
└── setup-lab.sh ← lab automation
| Date | Event |
|---|---|
| 2017 | Commit 72548b093ee3 introduces the bug in the kernel |
| ~2025 | Theori/Xint Code begins analysis of the crypto subsystem |
| Apr 28, 2026 | Coordination with distributors |
| Apr 29, 2026 | Public disclosure + PoC published |
| May 1, 2026 | Patched kernels available in production repositories |
| May 1, 2026 | Added to CISA KEV catalog |
a664bf3d603d