Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31431 — Working proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation via AF_ALG AEAD page cache corruption, granting root shell. | Kitploit
Tools/GitHubGitHub/wesmar/cve-2026-31431
Privilege EscalationExploit FrameworksVulnerability AnalysisExploitationBinary Exploitation
GitHubwesmar/cve-2026-31431

CVE-2026-31431

Working proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation via AF_ALG AEAD page cache corruption, granting root shell.

View Repository
6185 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431 — Local Privilege Escalation via AF_ALG

NVD / NIST PoC Download

2026-04-29 — I am publishing this exploit one day after sharing it on the MyDigitalLife forum. It does not require Python; it is written in C and compiled to the smallest possible size using:

musl-gcc -static -Os -o exploit exploit.c -s

Critical threat. The exploit binary is compiled without dependencies and can be used to test for vulnerabilities on any Linux system

CVE-2026-31431 is a NIST-confirmed vulnerability in the Linux kernel that allows an unprivileged local user to obtain a root shell in seconds. In light of the publicly circulating exploit for CVE-2026-31431, I have developed a binary proof-of-concept (PoC) to evaluate the exposure of our internal infrastructure. While some environments restrict the use of su, this vulnerability is particularly critical for shared servers because it targets the underlying kernel memory management. Consequently, any SETUID binary—including sudo, passwd, mount, or newgrp—can be leveraged to trigger the exploit and grant a root shell. Administrative action to patch the kernel is required immediately, as standard user-space restrictions are insufficient to mitigate this threat. Any Linux system running an unpatched kernel is at risk.

My Own Working Exploit · Linux Kernel · AF_ALG cryptographic interface (AEAD)

Replaces /usr/bin/su in the kernel page cache without touching the on-disk file

Local shell access is sufficient — no additional privileges required

Affects unpatched Linux distributions

CVE-2026-31431


📚 Table of Contents

  • What is this vulnerability
  • Who is affected
  • How the exploit works — step by step
  • Attack flow
  • Exploit code analysis
  • ELF payload — technical details
  • How to check if you are vulnerable
  • Mitigations
  • Researcher notes
  • Disclaimer

What is this vulnerability

CVE-2026-31431 is a bug in the handling of scatter-gather I/O operations and page cache references in the Linux kernel cryptographic subsystem — specifically in the AF_ALG socket implementation for AEAD algorithms (crypto/af_alg.c, crypto/aead.c).

PropertyValue
IdentifierCVE-2026-31431
ReferenceNIST NVD
TypeLocal Privilege Escalation (LPE)
ComponentLinux Kernel — AF_ALG / AEAD (authencesn)
Required accessUnprivileged local user
ImpactInteractive root shell
Exploit statusWorking PoC publicly available on GitHub
PersistenceNone — modification exists in RAM only; reboot restores the original state

What actually happens

The Linux kernel exposes a cryptographic interface to user space through AF_ALG sockets. The vulnerability lies in the fact that during an AEAD decryption operation, the kernel incorrectly maps the decryption output directly onto the page cache pages of the source file — instead of a temporary buffer. An attacker can thereby overwrite the in-memory content of any file without modifying it on disk, without root privileges, and without leaving any visible trace in the filesystem.


Who is affected

SystemStatus
Ubuntu 24.04 (bare metal / VM)⚠️ Vulnerable on unpatched kernel
Debian, Fedora, Arch on unpatched kernel⚠️ Vulnerable
Distributions with CONFIG_SECURITY_LOCKDOWN_LSM✅ Likely protected
Systems with nosuid or ProtectSUID (systemd)✅ Protected
Systems with AppArmor/SELinux blocking AF_ALG✅ Protected
macOS, Windows (native)✅ Not affected

How the exploit works — step by step

The exploit consists of two components: a helper script at /tmp/x and a corruption loop based on AF_ALG. The following is an exact walkthrough based on source code analysis:

1. Helper script setup

The exploit creates /tmp/x with the following content:

#!/bin/sh
export TERM=xterm-256color
exec /bin/sh

It sets permissions to 0755. The reason: /usr/bin/su strips environment variables (including TERM) on launch. The helper script restores them before spawning the real shell, ensuring a functional terminal.

2. ELF payload construction

A minimal 158-byte x86_64 ELF binary containing raw shellcode is built in memory. The string /bin/sh at offset 150 is then patched to /tmp/x\0 via memcmp/memcpy. See ELF Payload for details.

3. Opening /usr/bin/su read-only

int su_fd = open("/usr/bin/su", O_RDONLY);

The file is opened read-only — the exploit requires no write permissions whatsoever.

4. Corruption loop — 39 iterations of 4 bytes each

The payload (158 bytes) is processed in 4-byte chunks (39 complete chunks). Each chunk is passed through corrupt_binary_chunk(), which performs:

  • Creates an AF_ALG socket (SOCK_SEQPACKET)
  • Binds to authencesn(hmac(sha256),cbc(aes)) — a compound AEAD algorithm
  • Sets a 72-byte key and an authentication tag size of 4 bytes
  • Accepts an operation socket (op_sock)
  • Sends sendmsg with an 8-byte buffer (4× 'A' + 4 payload bytes) and three CMSGs: ALG_OP_DECRYPT, IV (20 bytes), assoclen=8
  • Performs splice: su_fd → pipe → op_sock (zero-copy through the kernel)
  • Finalises via recv() — this is where the kernel erroneously overwrites the page cache

5. Execution

execve("/usr/bin/su", args, NULL);

The kernel loads /usr/bin/su through the page cache — which is now poisoned. The SUID bit (chmod u+s) is intact, so the kernel executes the file as root. The shellcode runs setuid(0) → execve("/tmp/x") → interactive root shell.


Attack flow

flowchart TD
    A[Unprivileged local user] --> B["Creates /tmp/x helper script\nchmod 0755"]
    B --> C["Builds 158-byte ELF payload\nPatch: /bin/sh → /tmp/x"]
    C --> D["open /usr/bin/su O_RDONLY\nNo write permissions needed"]
    D --> E[Loop: 39 chunks of 4 bytes]
    E --> F[socket AF_ALG SOCK_SEQPACKET]
    F --> G["bind: authencesn hmac sha256 cbc aes"]
    G --> H["setsockopt: 72B key + authsize=4"]
    H --> I[accept → op_sock]
    I --> J["sendmsg: 8B data + 3x CMSG\nDECRYPT / IV 20B / assoclen=8"]
    J --> K["splice: su_fd → pipe → op_sock\nzero-copy through kernel"]
    K --> L[recv → finalise AEAD operation]
    L --> M["KERNEL BUG: decryption output\noverwrites page cache of su_fd"]
    M --> N{Next chunk?}
    N -->|Yes| E
    N -->|No| O["execve /usr/bin/su"]
    O --> P["Kernel loads /usr/bin/su\nfrom poisoned page cache"]
    P --> Q["SUID bit intact\nkernel executes as root"]
    Q --> R["Shellcode: setuid 0 syscall 105"]
    R --> S["execve /tmp/x syscall 59"]
    S --> T[Interactive root shell]

Exploit code analysis

Key sections of exploit.c reviewed below:

corrupt_binary_chunk() function

The heart of the exploit. Each call coordinates one complete AF_ALG transaction:

Download Tool