Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CopyFail-CVE-2026-31431 — Linux kernel LPE exploit (CVE-2026-31431) using AF_ALG + splice to overwrite setuid-binary page cache for root. No race conditions, works on all distros since 2017. | Kitploit
Tools/GitHubGitHub/zephrfish/copyfail-cve-2026-31431
Privilege EscalationExploitationPenetration TestingBinary Exploitation
GitHubzephrfish/copyfail-cve-2026-31431

CopyFail-CVE-2026-31431

Linux kernel LPE exploit (CVE-2026-31431) using AF_ALG + splice to overwrite setuid-binary page cache for root. No race conditions, works on all distros since 2017.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
241055 months agoReviewed by Kitploit

CopyFail: CVE-2026-31431

Python implementation of copy.fail. Overwrites the page cache of a setuid-root binary via AF_ALG + splice to get root. No race, no offsets works on any Linux distro since 2017.

Requirements

  • Python 3.6+ (3.12+ uses os.splice natively; older versions fall back to ctypes)
  • Linux kernel with authencesn(hmac(sha256),cbc(aes)) if missing: modprobe authencesn hmac cbc

Architectures

x86_64 i386/i686 armv6l/armv7l aarch64

Usage

python3 copyfail.py           # run exploit
python3 copyfail.py --check   # pre-flight diagnostics
python3 copyfail.py --scan    # find setuid-root binaries on this system

References

  • copy.fail
  • theori-io/copy-fail-CVE-2026-31431
Download Tool