
Linux kernel LPE exploit (CVE-2026-31431) using AF_ALG + splice to overwrite setuid-binary page cache for root. No race conditions, works on all distros since 2017.
Python implementation of copy.fail. Overwrites the page cache of a setuid-root binary via AF_ALG + splice to get root. No race, no offsets works on any Linux distro since 2017.
os.splice natively; older versions fall back to ctypes)authencesn(hmac(sha256),cbc(aes)) if missing: modprobe authencesn hmac cbcx86_64 i386/i686 armv6l/armv7l aarch64
python3 copyfail.py # run exploit
python3 copyfail.py --check # pre-flight diagnostics
python3 copyfail.py --scan # find setuid-root binaries on this system