
C exploit for CVE-2026-31431 (Copy Fail) targeting Linux AF_ALG splice vulnerability. Includes detection test and privilege escalation via /usr/bin/su page cache manipulation to gain root shell.
CVE-2026-31431 (Copy Fail) C language PoC, logically aligned with the original Python exploit theori-io/copy-fail-CVE-2026-31431.
For authorized security research and experimental environments only. Do not use on unauthorized systems.
In Linux AF_ALG, authencesn(hmac(sha256),cbc(aes)) under the splice + AEAD path can write 4 bytes from AAD into the page cache of the target file (disk content unchanged).
This repository's exploit behavior is consistent with the original:
/usr/bin/su.su, which loads the fake su from the tampered page cache, typically obtaining a root shell without a password.copy-fail/
├── include/
│ ├── copy_fail.h
│ └── su_payload_zlib.h
├── src/
│ ├── alg.c # AF_ALG / splice 原语
│ ├── util.c # 前置检查
│ ├── test_main.c # 漏洞检测
│ └── exploit_main.c # 提权
├── Makefile
└── README.md
Ubuntu / Debian:
sudo apt install build-essential zlib1g-dev
cd copy-fail
make
Generates:
| Artifact | Description |
|---|---|
bin/copy-fail-test | Vulnerability test (temporary sentinel file, does not modify system files) |
bin/copy-fail-exploit | Privilege escalation (modifies /usr/bin/su page cache then exec su) |
After compiling on a high-version system, if you encounter GLIBC_2.34 / GLIBC_2.38 not found, execute on the build machine:
make static
Copy bin/copy-fail-test and bin/copy-fail-exploit to the target machine and run. Alternatively, run make on the target machine from source (dynamic linking, smaller size).
./bin/copy-fail-test
echo $?
| Exit Code | Meaning |
|---|---|
| 0 | No vulnerability characteristics observed / prerequisites not met |
| 2 | Vulnerability characteristics present |
| 1 | Test process error |
./bin/copy-fail-exploit
id
No output is by design; on success, you enter a root shell. On failure, echo $? typically returns 1.
AF_ALG socketbind algorithm authencesn(hmac(sha256),cbc(aes))/usr/bin/susplice can write to AF_ALG socketIf the tester reports cannot be instantiated (No such file or directory):
grep -r algif_aead /etc/modprobe.d/
sudo modprobe algif_aead
grep authencesn /proc/crypto
Some distributions disable algif_aead via modprobe (e.g., Ubuntu USN mitigation), so you need to re-enable it on a root experimental machine before testing.
After privilege escalation testing (in root shell), you can discard the page cache contamination:
echo 3 > /proc/sys/vm/drop_caches
Or restart the virtual machine.