Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31431-C — C exploit for CVE-2026-31431 (Copy Fail) targeting Linux AF_ALG splice vulnerability. Includes detection test and privilege escalation via /usr/bin/su page cache manipulation to gain root shell. | Kitploit
Tools/GitHubGitHub/yangh-beep/cve-2026-31431-c
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingRed TeamingBinary Exploitation
GitHubyangh-beep/cve-2026-31431-c

CVE-2026-31431-C

C exploit for CVE-2026-31431 (Copy Fail) targeting Linux AF_ALG splice vulnerability. Includes detection test and privilege escalation via /usr/bin/su page cache manipulation to gain root shell.

View Repository
64 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

copy-fail

CVE-2026-31431 (Copy Fail) C language PoC, logically aligned with the original Python exploit theori-io/copy-fail-CVE-2026-31431.

For authorized security research and experimental environments only. Do not use on unauthorized systems.

Brief Principle

In Linux AF_ALG, authencesn(hmac(sha256),cbc(aes)) under the splice + AEAD path can write 4 bytes from AAD into the page cache of the target file (disk content unchanged).

This repository's exploit behavior is consistent with the original:

  1. Write the zlib-decompressed miniature ELF 4 bytes at a time into the page cache of /usr/bin/su.
  2. Execute su, which loads the fake su from the tampered page cache, typically obtaining a root shell without a password.

Directory Structure

copy-fail/
├── include/
│   ├── copy_fail.h
│   └── su_payload_zlib.h
├── src/
│   ├── alg.c           # AF_ALG / splice 原语
│   ├── util.c          # 前置检查
│   ├── test_main.c     # 漏洞检测
│   └── exploit_main.c  # 提权
├── Makefile
└── README.md

Dependencies

Ubuntu / Debian:

sudo apt install build-essential zlib1g-dev

Build

cd copy-fail
make

Generates:

ArtifactDescription
bin/copy-fail-testVulnerability test (temporary sentinel file, does not modify system files)
bin/copy-fail-exploitPrivilege escalation (modifies /usr/bin/su page cache then exec su)

Static Build (for copying to machines with older glibc)

After compiling on a high-version system, if you encounter GLIBC_2.34 / GLIBC_2.38 not found, execute on the build machine:

make static

Copy bin/copy-fail-test and bin/copy-fail-exploit to the target machine and run. Alternatively, run make on the target machine from source (dynamic linking, smaller size).

Usage

Test

./bin/copy-fail-test
echo $?
Exit CodeMeaning
0No vulnerability characteristics observed / prerequisites not met
2Vulnerability characteristics present
1Test process error

Privilege Escalation

./bin/copy-fail-exploit
id

No output is by design; on success, you enter a root shell. On failure, echo $? typically returns 1.

Prerequisites

  • Kernel can create AF_ALG socket
  • Can bind algorithm authencesn(hmac(sha256),cbc(aes))
  • Read permission on /usr/bin/su
  • splice can write to AF_ALG socket

If the tester reports cannot be instantiated (No such file or directory):

grep -r algif_aead /etc/modprobe.d/
sudo modprobe algif_aead
grep authencesn /proc/crypto

Some distributions disable algif_aead via modprobe (e.g., Ubuntu USN mitigation), so you need to re-enable it on a root experimental machine before testing.

Cleanup

After privilege escalation testing (in root shell), you can discard the page cache contamination:

echo 3 > /proc/sys/vm/drop_caches

Or restart the virtual machine.

References

  • CVE-2026-31431
  • theori-io/copy-fail-CVE-2026-31431
Download Tool