Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31431-exploit — Linux local privilege escalation exploits for CVE-2026-31431, including raw and recoverable workflows. | Kitploit
Tools/GitHubGitHub/wuwu001/cve-2026-31431-exploit
Privilege EscalationExploit FrameworksExploitationPenetration TestingRed TeamingBinary Exploitation
GitHubwuwu001/cve-2026-31431-exploit

CVE-2026-31431-exploit

Linux local privilege escalation exploits for CVE-2026-31431, including raw and recoverable workflows.

View Repository
4145 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431

Language: English 语言:中文 Release Download Prebuilt

WARNING

These Linux LPE exploit implementations are runtime-destructive.

They overwrite the live page-cache view of privileged targets such as:

  • su
  • PAM configuration files
  • any file passed into patch mode

This is usually not a normal persistent on-disk edit, but it does change runtime behavior and can affect authentication / privilege flow immediately.

This repository does not provide a fully non-destructive root mode.


Files

  • copyfail_raw_su_root.c
  • copyfail_portable_lpe.c

Both are Linux-only.

Prebuilt binaries for additional architectures may be added in future updates.


Build

copyfail_portable_lpe.c

gcc -O2 -s copyfail_portable_lpe.c -o copyfail_portable_lpe

copyfail_raw_su_root.c

gcc -O2 -s copyfail_raw_su_root.c -o copyfail_raw_su_root

Default behavior

For copyfail_portable_lpe.c, running:

./copyfail_portable_lpe

uses auto-revert by default.

That means it will try the recoverable workflow first:

  1. patch the target
  2. gain root
  3. attempt to revert the patched target
  4. then hand off to a root shell

If recoverable mode fails, the program prints fallback mode hints.


copyfail_raw_su_root.c

Minimal raw variant:

  • directly patches su
  • immediately executes the target su
  • minimal logic

Architecture

  • x86_64 Linux only

Run

./copyfail_raw_su_root

copyfail_portable_lpe.c

General variant with multiple modes.

Modes

auto

Explicit non-reverting mode:

./copyfail_portable_lpe auto

auto-revert

Recoverable-first mode:

./copyfail_portable_lpe
./copyfail_portable_lpe auto-revert

helper

Drop a SUID bash helper without revert:

./copyfail_portable_lpe helper ./.rootsh

helper-revert

Drop a helper, then attempt to restore patched targets:

./copyfail_portable_lpe helper-revert ./.rootsh

patch

Same-length string replacement on a chosen file:

./copyfail_portable_lpe patch <file> <find> <replace>

raw-su-elf

Raw su patch path:

./copyfail_portable_lpe raw-su-elf

Recoverable logic

auto-revert and helper-revert are still destructive during exploitation.

They are only "recoverable" in the sense that they:

  1. patch the live runtime target
  2. use the patched state to obtain root
  3. attempt to restore the patched target before handing off control

So this is destructive-then-revert, not truly non-destructive.

Architecture

  • auto / auto-revert / helper / helper-revert / patch: Linux-oriented, less tightly coupled to CPU architecture when compiled on-target
  • raw-su-elf: x86_64 Linux only

Disclaimer

This repository is provided for:

  • security research
  • defensive testing
  • lab / CTF / educational use
  • authorized vulnerability validation

Do not use these materials against systems, accounts, or networks without explicit permission from the owner.

The author and contributors provide this content as-is, without warranty, and accept no responsibility for misuse, damage, data loss, service disruption, or legal consequences resulting from use of the code or techniques in this repository.

Download Tool