Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-31431 — Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide, and lab environment. | Kitploit
Tools/GitHubGitHub/vasyapokemon/cve-2026-31431
Privilege EscalationVulnerability AnalysisExploitationMalware AnalysisDigital ForensicsIntrusion DetectionPapers & ResearchLearning & EducationIncident ResponseCurated ResourcesLabs & Practice
245 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
vasyapokemon/cve-2026-31431

cve-2026-31431

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide, and lab environment.

View Repository

CVE-2026-31431 — "Copy Fail": Linux Kernel algif_aead Local Privilege Escalation

CISA KEV | CVSS 7.8 HIGH | Affects Linux kernels 4.14 – early 2026 (~9 years)


Table of Contents

  1. Executive Summary
  2. Risk Assessment
  3. Technical Deep Dive
  4. Attack Methodology — Red Team
  5. Detection & Incident Response — Blue Team
  6. Patching & Remediation
  7. Lab Environment
  8. References

1. Executive Summary

CVE-2026-31431, nicknamed "Copy Fail", is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel's cryptographic subsystem. A low-privileged local user can escalate to root in seconds on any unpatched system.

AttributeValue
CVECVE-2026-31431
NicknameCopy Fail
CVSS v3.17.8 HIGH
Attack VectorLocal
Privileges RequiredLow
User InteractionNone
Componentcrypto/algif_aead.c — authencesn template
Introduced2017 (commit 72548b093ee3)
Disclosed2026
Years Silent~9 years
CISA KEVYes
Public PoCYes (732-byte standalone Python script)

Business Impact

  • Root access on any unpatched Linux server, VM, cloud instance, or container host
  • Container escape from Kubernetes pods — page cache is shared with the host kernel
  • Zero on-disk footprint — exploitation leaves no file changes, no dirty pages, no audit trail via standard file integrity tools (Tripwire, AIDE)
  • Affects Red Hat, Ubuntu, Debian, SUSE, Amazon Linux, and virtually all major distributions running kernels from 2017 onward

Recommended Immediate Action

  1. Temporary mitigation (deploy now, no reboot required if module not loaded):
    echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif-aead.conf
    sudo rmmod algif_aead 2>/dev/null || true
    
  2. Permanent fix: Update kernel packages via your distribution's package manager and reboot.
  3. Verify: Run detection/check_vulnerable.sh before and after remediation.

2. Risk Assessment

CVSS 3.1 Vector String

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
MetricValueRationale
Attack VectorLocalRequires shell access (SSH, container exec, physical)
Attack ComplexityLowReliable, fully automated — no race condition required
Privileges RequiredLowAny unprivileged user account
User InteractionNoneNo victim interaction needed
ConfidentialityHighFull system compromise
IntegrityHighFull system compromise
AvailabilityHighFull system compromise

Threat Landscape

FactorAssessment
PoC AvailabilityPublic, weaponized, 732-byte standalone Python
Exploit ReliabilityHigh — works across tested distros without modification
Detection DifficultyHigh — no disk writes, no dirty pages
Attacker Skill RequiredLow — script kiddie with public PoC
CISA KEVAdded 2026 — actively monitored
Microsoft DefenderFlagged as under active investigation

Affected Environments

EnvironmentRisk
Bare-metal Linux serversCritical
Linux VMs (cloud or on-prem)Critical
Kubernetes nodesCritical (also enables container escape)
Docker hostsCritical
Shared hosting / multi-tenantCritical
WSL2 / Linux on WindowsAssess per kernel version

3. Technical Deep Dive

3.1 Background: AF_ALG and AEAD

The Linux kernel exposes cryptographic operations to userspace via AF_ALG sockets (AF_ALG = 38). This interface (algif_aead) allows unprivileged applications to invoke kernel crypto hardware accelerators without needing kernel-mode code.

AEAD (Authenticated Encryption with Associated Data) algorithms like AES-GCM and ChaCha20-Poly1305 are widely used for TLS, disk encryption, and VPN protocols. The vulnerable template is authencesn — an AEAD composition using hmac(sha256) + cbc(aes) with Extended Sequence Number (ESN) support, commonly used in IPsec.

3.2 Root Cause

In 2017, commit 72548b093ee3 introduced in-place AEAD operation to algif_aead as a performance optimization — allowing the crypto engine to read and write the same buffer. This was flawed:

The bug chain:

1. Caller binds AF_ALG socket to:
      authencesn(hmac(sha256),cbc(aes))

2. Caller sends a decryption request via sendmsg() with specific flags

3. Caller uses splice() to feed PAGE CACHE PAGES from an open file
   descriptor directly into the socket's scatterlist

4. The authencesn template, during ESN header processing, uses the
   OUTPUT BUFFER as scratch space — writing 4 bytes past the
   expected output boundary

5. Because the scatterlist contains page cache pages (not private
   copies), this scratch write lands DIRECTLY IN THE PAGE CACHE

6. Page cache is shared kernel-wide — all processes reading the
   same file now see the modified bytes

Key insight: splice() is zero-copy — it hands page cache references
to the socket. The in-place "optimization" then writes INTO those
pages. No dirty bit is set because the write goes through the crypto
engine, not the normal write path.

3.3 The Write Primitive

The vulnerability provides a controlled 4-byte write into the page cache of any file the attacker can open for reading:

PropertyValue
Write size4 bytes
Offset controlYes — attacker-controlled via splice offset
TargetPage cache of any readable file
Dirty page markingNone
On-disk modificationNone
Timestamp updateNone
Kernel log entryNone (unless auditd configured)

The write is repeatable — the exploit loops the 4-byte write to patch larger code sequences.

3.4 Exploitation Chain

[1] Open /usr/bin/su (or any setuid-root binary) for reading
    ↓
[2] Map a copy to find target instruction bytes
    (e.g., UID check, execve path, security gate)
    ↓
[3] Compute exact page cache offset of target bytes
    ↓
[4] Set up AF_ALG socket → authencesn(hmac(sha256),cbc(aes))
    ↓
[5] splice() the target binary's page cache into the socket
    ↓
[6] Trigger decryption → authencesn scratch write patches
    the target bytes in page cache (4 bytes per iteration)
    ↓
[7] Repeat for each 4-byte patch needed
    ↓
[8] Execute /usr/bin/su → runs root-owned setuid binary
    but now with attacker-controlled code in page cache
    ↓
[9] Root shell

3.5 Why Standard Defenses Fail

DefenseBypassed?Reason
File Integrity Monitoring (Tripwire/AIDE)YesNo on-disk change
IDS file hash checksYesDisk bytes unchanged
inotify file watchYesNo VFS write event
SELinux / AppArmorPartialControls process, not page cache write via crypto engine
Read-only mountsYesPage cache modified in-memory, not via mount
auditd watch on binaryYesAudit watches VFS writes — this bypasses VFS

3.6 Affected Kernel Versions

BranchVulnerable ThroughFixed From
4.14.xAll (vulnerability origin)No upstream fix (EOL)
5.4.x (LTS)AllDistribution backport required
5.10.x (LTS)AllDistribution backport required
5.15.x (LTS)AllDistribution backport required
6.1.x (LTS)≤ 6.1.1296.1.130+
6.6.x (LTS)≤ 6.6.866.6.87+
6.12.x (LTS)≤ 6.12.226.12.23+
6.15-rcFixed in rc6.15-rc+
Download Tool