
CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script
CVE-2026-31431 (Copy Fail) is a Linux kernel local privilege escalation vulnerability that exploits AF_ALG sockets (address family 38) combined with the splice() zero-copy system call to bypass file write permissions and tamper with the page cache, enabling modification of SUID binaries without write permission and subsequently gaining root privileges.
socket(AF_ALG, SOCK_SEQPACKET, 0) # Create AF_ALG socket
-> bind(authesn(hmac(sha256),cbc(aes))) # Bind AEAD encryption template
-> sendmsg(AEAD operation) # Trigger kernel crypto path
-> splice(-> target file) # Zero-copy write, bypassing permission checks
-> Tamper with SUID files like /usr/bin/su # Escalate to root
| Kernel Branch | Affected Range | Fixed Version |
|---|---|---|
| mainline / 6.19.x | < 6.19.12 | >= 6.19.12 |
| 6.18.x (stable) | < 6.18.22 | >= 6.18.22 |
| 6.12.x (LTS) | < 6.12.23 | >= 6.12.23 |
| 6.6.x (LTS) | < 6.6.87 | >= 6.6.87 |
| 6.1.x (LTS) | < 6.1.130 | >= 6.1.130 |
| 4.14 ~ < 7.0 | All affected | Upgrade to a secure version |
| < 4.14 | Not affected | - |
| >= 7.0 | Fix included | - |
# Download the script
wget https://raw.githubusercontent.com/tangjie1/CVE-2026-31431-Check/main/cve-2026-31431-check.sh
# Grant execute permission and run (requires root)
chmod +x cve-2026-31431-check.sh
sudo ./cve-2026-31431-check.sh
# Non-interactive mode (for automation/CI)
sudo ./cve-2026-31431-check.sh --non-interactive
| ID | Check Item | Description |
|---|---|---|
| [1.0] | Affected version range table | Shows affected/fixed version comparison for each branch |
| [1.1] | Kernel version | Compared against known affected ranges and fixed baselines |
| [1.2] | algif_aead module status | Four states: built-in / loaded / present but loadable on demand / absent |
| [1.3] | authencesn crypto template | Whether available in /proc/crypto |
| [1.4] | Mitigations | initcall_blacklist + modprobe.d blacklist |
| [1.5] | Comprehensive assessment | Multi-factor cross-check yielding safe/medium/high/critical conclusion |
| ID | Check Item | Description |
|---|---|---|
| [2.1] | SUID page cache detection | dd direct I/O vs cached hash comparison |
| [2.2] | Module load history | dmesg + lsmod load duration |
| [2.3] | Shell history scan | Keyword matching across all users' .bash_history |
| [2.4] | System file detection | UID=0 anomalous users / passwd & SUID modification times |
| [2.5] | Temporary directory scan | Suspicious files in /tmp /var/tmp /dev/shm within the last 24h |
| [2.6] | System log audit | su failure records + sudo vulnerability keywords |
| [2.7] | Container escape detection | Docker environment + seccomp + /proc/1/root |
| Method | Principle | Reboot Required | Applicable Scenario |
|---|---|---|---|
| Method 1 | modprobe.d blacklist + rmmod | No | CONFIG=m (module mode) |
| Method 2 | initcall_blacklist kernel parameter | Yes | CONFIG=y (built-in mode) or defense in depth |
| Method 3 | Upgrade kernel to a secure version | Yes | Permanent fix (recommended) |
Ubuntu / Debian / Kali / CentOS / RHEL / Rocky / AlmaLinux / Fedora / openSUSE / Arch Linux / Alpine Linux
MIT License
This tool is intended for security research and authorized penetration testing only. Users must ensure compliance with local laws and regulations and use it only on target systems for which they have obtained explicit authorization. The developer assumes no responsibility for any consequences of unauthorized use.