Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CopyFail-Exploits-CVE-2026-31431 — Multi-language educational exploit implementations for CVE-2026-31431, a Linux kernel local privilege escalation via the algif_aead module, with a safe detector and CTF usage guidance. | Kitploit
Tools/GitHubGitHub/shotafry/copyfail-exploits-cve-2026-31431
Privilege EscalationExploit FrameworksExploitationCTFLearning & EducationBinary ExploitationLabs & Practice
GitHubshotafry/copyfail-exploits-cve-2026-31431

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CopyFail-Exploits-CVE-2026-31431

Multi-language educational exploit implementations for CVE-2026-31431, a Linux kernel local privilege escalation via the algif_aead module, with a safe detector and CTF usage guidance.

View Repository
7215 months agoNot yet reviewed

CVE-2026-31431 — Copy Fail

Educational repository with multi-language implementations of the Copy Fail exploit.
Created and maintained by @shotafry — because reading the CVE is not enough. You have to reproduce it.


📖 Leer en Español


Table of Contents

  • What is Copy Fail?
  • Who discovered it?
  • Severity and CVSS
  • How does it work?
  • Requirements
  • Available implementations
  • Usage by language
  • System verification
  • What exactly happens when you run it?
  • CTF and testing environments
  • Obfuscation — silent variants
  • Mitigation and patch
  • Repository structure
  • Legal disclaimer

What is Copy Fail?

Copy Fail is a local privilege escalation (LPE) vulnerability in the Linux kernel, catalogued as CVE-2026-31431. It affects the kernel's cryptographic subsystem, specifically the algif_aead module that handles authenticated encryption (AEAD) operations through AF_ALG sockets.

The bug was introduced in 2017 as part of an optimization in the authencesn module and went undetected for nearly 9 years, present in virtually every modern Linux distribution.

What makes Copy Fail special compared to other historical LPEs:

FeatureCopy FailTypical LPE
Requires race condition❌ No✅ Yes
Requires kernel-specific offset❌ No✅ Yes
Works across all distros✅ Yes❌ Usually not
Reliability100% deterministicVariable
Modifies disk❌ No (RAM only)Depends

Who discovered it?

The vulnerability was discovered by Taeyang Lee from Theori's research team. The full exploit chain was developed by the Xint Code Research team, who documented the process using AI-assisted analysis of the Linux kernel's crypto/ subsystem.

The public disclosure includes a functional PoC, complete technical analysis and documentation at copy.fail.


Severity and CVSS

CVE:       CVE-2026-31431
CVSS:      7.8 — HIGH
Vector:    Local
Impact:    Full privilege escalation (root)
Distros:   All Linux distributions with kernel >= 2017 (unpatched)

The CVSS score is 7.8 and does not reach critical (9+) solely because it requires prior local access — the attacker must already have a session on the system. In cloud environments and with Docker containers, this requirement is considerably easier to meet than it appears.


How does it work?

The kernel page cache

The Linux kernel stores recently read files in RAM. This is called the page cache. When a process reads /etc/passwd, the kernel does not go to disk — it serves the in-memory copy. This is faster, but creates an attack surface: if you can modify that RAM copy without touching the disk, the system will see falsified data.

The bug in algif_aead

The algif_aead module allows AEAD operations from user space via AF_ALG sockets. The bug lies in the 2017 optimization: when splice() is used to pass pages from a file into the socket, those page cache pages end up in the destination (writable) scatter-gather list of the cryptographic operation.

Result: any unprivileged user can write 4 controlled bytes into any file they can read, without touching the disk.

Exploitation flow

Unprivileged user
        │
        ▼
  Opens AF_ALG socket (authencesn)
        │
        ▼
  sendmsg() — AEAD parameters with our 4 bytes in seqno_lo
        │
        ▼
  splice() — file → pipe → op socket
  [BUG] The file's page cache pages end up in the destination scatterlist
        │
        ▼
  recv() triggers the AEAD operation
  Auth check fails (EBADMSG) but the scratch-write already happened
        │
        ▼
  /etc/passwd (page cache) now says: user → UID 0
        │
        ▼
  su <user> → PAM validates real password → setuid(0) → ROOT

Simple analogy

Imagine the kernel has a castle registry book (/etc/passwd). Copy Fail is like discovering that if you open the castle's magic workshop in a very specific order, the registry book accidentally ends up on your workbench — and you can change your rank from "foot soldier" to "king" with a pen. The clerk (PAM) checks your password but doesn't check the original book, only the copy in front of them. You're king.

¿what happens at execute?

passwd cambiando en tiempo real

Example with exploit in C


Requirements

Target system

  • Linux kernel >= ~2017 without the CVE-2026-31431 patch
  • algif_aead module available and loadable
  • 4-digit UID (1000–9999) — standard on all distros

Quick verification

# Check kernel version
uname -a

# Check if the algorithm is available
grep -i authencesn /proc/crypto

# Check if the module is loaded
lsmod | grep alg

If grep -i authencesn /proc/crypto returns authencesn(hmac(sha256),cbc(aes)), the system is vulnerable.

Per language

LanguageTarget requirementPre-compilation needed
CNone (static binary)gcc on build machine
PythonPython 3.10+No
RustNone (static binary)rustc on build machine
GoNone (static binary)go on build machine
RubyRuby + fiddle gem (included by default)No
PerlPerl 5 (present on virtually all Linux)No

Available implementations

This repository contains the exploit implemented in 6 languages, all functionally equivalent, with educational comments in Spanish.

copy_fail_exploit.c      → C       — static binary, zero dependencies
copy_fail_exploit.py     → Python  — most readable, ideal for learning
copy_fail_exploit.rs     → Rust    — the irony: "safe" language exploits kernel
copy_fail_exploit.go     → Go      — static binary, highly portable
copy_fail_exploit.rb     → Ruby    — ubiquitous on Rails servers
copy_fail_exploit.pl     → Perl    — the quietest, present on all Linux
test_cve_2026_31431.py   → Detector — checks vulnerability without exploiting anything

Usage by language

Detector (always run this first)

python3 test_cve_2026_31431.py
  • Exit 0 → NOT vulnerable
  • Exit 2 → VULNERABLE
  • Exit 1 → Test error

C

gcc copy_fail_exploit.c -o copy_fail_c
./copy_fail_c           # dry-run (cleans up, leaves no trace)
./copy_fail_c --shell   # full exploit

Python

python3 copy_fail_exploit.py
python3 copy_fail_exploit.py --shell

Rust

rustc copy_fail_exploit.rs -o copy_fail_rs
./copy_fail_rs
./copy_fail_rs --shell

Go

go build -o copy_fail_go copy_fail_exploit.go
./copy_fail_go
./copy_fail_go --shell

Ruby

ruby copy_fail_exploit.rb
ruby copy_fail_exploit.rb --shell

Perl

perl copy_fail_exploit.pl
perl copy_fail_exploit.pl --shell

Installing languages (if needed)

Download Tool