Copy Fail (CVE-2026-31431) is a local privilege-escalation vulnerability in the Linux kernel's AF_ALG AEAD processing, involving algif_aead and the authencesn cryptographic template. Unsafe in-place processing of data from different mappings allows AF_ALG operations combined with splice() to produce controlled four-byte writes into the page cache of readable files. An unprivileged attacker can corrupt the cached contents of a privileged executable without modifying its on-disk contents and use subsequent execution to obtain root privileges. Exploitation from containers can compromise the shared host kernel under suitable conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
26 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (361 hidden).
This 93-file repository is an operational Kubernetes container-escape PoC for Linux kernel CVE-2026-31431 (Copy Fail), not a detection-only tool. Its Go entry point, cmd/copyfail/main.go, embeds a statically compiled C payload and invokes internal/exploit. The exploit opens kube-proxy-associated utilities read-only, then repeatedly performs an AF_ALG AEAD socket and splice sequence in four-byte windows to poison their page-cache content. It targets ipset, legacy/nft xtables multi-call binaries, and nft so execution can occur across kube-proxy proxy modes. The intended privilege transition relies on shared overlay/container-image lower layers: a privileged kube-proxy DaemonSet subsequently executes a poisoned shared binary. Three build/deployment variants support an upstream/ACK-style kube-proxy image, Amazon EKS, and Google GKE. Dockerfiles deliberately inherit from the corresponding target or matching base image; deploy manifests run the PoC container and retain it with a long sleep. The C payloads use bundled Linux nolibc headers to build a small static executable without a normal libc. They are validation payloads rather than remote shells: once executed by privileged kube-proxy, they attempt host-disk mounts and create marker files, including /mnt/root/res and GKE stateful-partition paths. Documentation records tested image layers, privileged kube-proxy configurations, and affected cloud-node layouts. No command-and-control endpoint, reverse shell, credential exfiltration, or network callback is implemented.
This is a small standalone Python repository containing GPL-3.0 licensing, a README, and exploit.py. The Python program is an operational local privilege-escalation exploit for CVE-2026-31431, described as “Copy Fail.” It uses Linux AF_ALG AEAD sockets together with splice operations to place attacker-selected four bytes into a readable file's page-cache page. It targets /etc/passwd and searches for the root account's supported password-field markers, then changes four cached bytes so the root entry is interpreted as passwordless. The on-disk passwd file is not directly written. After validating the cached bytes with a fresh read, it instructs the operator to run su or, with --shell, executes su directly. Default behavior calls POSIX_FADV_DONTNEED to evict the cached page; --clean performs only this cleanup and --noclean deliberately retains the transient altered cache state. The README notes that this can expose passwordless root access to other local users until cleanup and that behavior depends on Debian-like PAM/passwd handling. No external network connection, C2 endpoint, downloaded payload, persistence mechanism, or framework integration is present.
The repository contains a README and two implementations claiming CVE-2026-31431, a local Linux privilege-escalation issue involving the AF_ALG crypto API. The primary artifact is copy_fail_exp.py, a compact Python 3 program that creates an AF_ALG AEAD socket (algorithm authencesn(hmac(sha256),cbc(aes))), configures ancillary crypto parameters, and combines a pipe with os.splice to attempt writes into page-cache-backed data from /usr/bin/su at selected offsets. It decompresses a fixed embedded byte payload, applies it in four-byte chunks, and runs su afterward. This is an operational but hard-coded PoC rather than a configurable framework module. The C file is materially less complete: it binds and accepts an AF_ALG socket, reads 4096 bytes from /usr/bin/su, writes those bytes to the operation socket, and invokes su, but it contains no splice/page-cache overwrite mechanism and is unlikely to achieve the documented elevation on its own. The README documents prerequisites, checks, mitigation, and a remote delivery example. The CVE, broad kernel-version claims, and exact payload effect are asserted by the repository and cannot be validated solely from the supplied code.
This three-file repository contains an MIT license, a Chinese-language README, and one Python 3 exploit entry point, copy-fail-dual-arch.py. It presents a local privilege-escalation exploit for the claimed CVE-2026-31431 "Copy Fail" AF_ALG/algif_aead page-cache corruption issue. The script detects x86_64 or AArch64, decompresses a corresponding embedded ELF/shellcode payload, opens the hard-coded setuid target /usr/bin/su read-only, and repeatedly calls corrupt_page() to write four-byte payload fragments through an AF_ALG AEAD socket and os.splice(). The intended primitive places file page-cache pages into a writable cryptographic scatterlist, allowing the cached executable image—not necessarily the persistent disk file—to be altered. Finally, it invokes su so the corrupted cached binary purportedly executes a setuid(0) plus /bin/sh root-shell payload. The exploit is standalone, has no framework dependency, performs no network communications, and uses only local kernel interfaces and filesystem targets. Its payload, target path, crypto algorithm, and supported architectures are hard-coded, making it an operational but non-customizable PoC-style exploit.
This is a Linux-only Go and C proof-of-concept for CVE-2026-31431 (“Copy Fail”), presented as a Kubernetes container-escape chain. cmd/copyfail/main.go embeds a statically compiled nolibc payload and invokes internal/exploit. The exploit opens a target file read-only (default /usr/sbin/ipset), splits the payload into 4-byte chunks, and for each chunk creates an AF_ALG AEAD socket, sends controlled data with MSG_MORE, then splices progressively larger portions of the target through a pipe into the socket. The intended result is corruption of the target file's page-cache pages through the AF_ALG splice CoW failure. The Dockerfile inherits from registry.k8s.io/kube-proxy:v1.35.2, deliberately preserving a shared lower image layer with kube-proxy. deploy/poc.yaml deploys the resulting image and executes /bin/copyfail -target /usr/sbin/ipset before sleeping. The intended cross-container effect is that kube-proxy on the same node later executes the poisoned shared-layer ipset binary from its privileged, host-networked context. Notably, the deployment sets allowPrivilegeEscalation: false but does not set runAsNonRoot: true; regardless, the claimed privilege transition relies on later execution by kube-proxy, not direct elevation in the PoC process. payload/payload.c is a small statically compiled validation payload using the bundled multi-architecture Linux nolibc headers. It mounts hard-coded /dev/vda3 as ext4 at /mnt and writes /mnt/root/res with a success marker. The repository also includes Makefile build automation, a GitHub Actions image-publishing workflow, Kubernetes manifests, and ACK/kube-proxy image metadata and command logs offered as validation artifacts. There is no external command-and-control, HTTP request, DNS lookup, or network callback in the exploit implementation.
This 18-file C/Bash/Docker research repository implements and documents CVE-2026-31431 ("Copy Fail"), a local Linux kernel AF_ALG AEAD flaw. It composes in-place AEAD decryption, zero-copy splice delivery of readable file page-cache pages, and an authencesn ESN scratch write to obtain a deterministic four-byte attacker-controlled page-cache write at a chosen file offset before authentication fails with EBADMSG. The primary exploit capability is local privilege escalation through volatile modification of a SUID executable's cached code/data while preserving the on-disk binary. The poc/ directory contains detector.c, a safe differential detector that creates and attacks only its own probe.bin; lpe.c, an operational lab-only escalation demo against a custom secretgate SUID program; and sgl-stress.c, a scatterlist edge-condition/availability test harness. The lab/ directory supplies a Docker-based, QEMU-booted A/B/C kernel harness, building a vulnerable 5.15.y parent, a revert-only variant that demonstrates an authencesn NULL-dereference panic, and a full companion-fixed variant. The custom SUID target and root-only flag are packed into an initramfs, while an ext4 virtio image permits validation that the exploit modifies only page cache and not disk. Documentation provides root-cause analysis, fix-commit mapping, PTES reporting, and prior-art attribution. This is not merely a detector: lpe.c contains a complete hardcoded local exploitation chain, although its target is intentionally confined to a disposable lab binary.
The repository is a small Visual Studio-oriented C++20 project containing one substantive source file, LinuxEXP/Main.cpp. It ports a referenced Python exploit for CVE-2026-31431. On Linux, the code opens /usr/bin/su read-only, decompresses an embedded obfuscated payload, and repeatedly calls copy_fail() for each four-byte payload chunk. The primitive creates an AF_ALG AEAD socket, configures a fixed key and authentication size, supplies control messages, then combines sendmsg(..., MSG_MORE), pipe(), and two splice() calls from the target file through the pipe into the algorithm socket. This is intended to exploit an erroneous kernel copy path to alter data associated with the otherwise read-only target file. It finally executes su, explicitly expecting a patched ELF that opens a root shell. The payload, key, and compressed bytes are split into strings to reduce static AV signature matching. The included .slnx and .vcxproj build a Windows console application, but __linux__ conditionals mean a Windows-built executable only prints Linux compilation instructions; actual exploitation requires compiling Main.cpp on Linux with -lz. No remote host, C2, or network service is contacted.
This three-file repository contains one Python exploit, a README, and Portuguese usage notes. EXPLOIT-CVE-2026_31431.py is a purported Linux local privilege-escalation exploit for CVE-2026-31431 ('Copy Fail'). Its write4() function opens /etc/passwd read-only, primes its page cache, then uses AF_ALG AEAD sockets and splice() to attempt a four-byte page-cache-only write. main() locates the invoking user's UID field and replaces a four-digit UID with 0000; it verifies the cached bytes, optionally executes su <user>, and otherwise requests cache eviction through POSIX_FADV_DONTNEED. The intended effect is a root shell without modifying /etc/passwd on disk. Notably, the script includes an unrelated and deliberately obscured scanningports() function that is called at startup. Despite its benign-looking name/comments, it decodes one of two GitHub raw-content URLs, disables HTTPS certificate verification, writes a downloaded script to the temporary directory, and silently executes it. This creates a separate network-delivered remote-code-execution capability and is inconsistent with the README's claim that the toolkit is pure Python standard library. The documentation also references filenames (test_cve_2026_31431.py and exploit_cve_2026_31431.py) that are not present or do not match the repository's actual uppercase exploit filename. There is no detector script in the supplied repository despite the README claiming one exists.
This five-file repository contains two local Linux privilege-escalation PoCs plus defensive detection and mitigation tooling for the claimed Copy Fail vulnerability, CVE-2026-31431. The principal implementations are copy_fail.c and copy_fail.py. Both first test whether an AF_ALG SOCK_SEQPACKET AEAD socket can bind the authencesn(hmac(sha256),cbc(aes)) algorithm. During exploitation, they configure an AF_ALG decryption request, splice progressively larger ranges from a read-only target file through a pipe into that request, and use the alleged AEAD output-boundary bug to place attacker-controlled four-byte values into the target file's page-cache pages. They repeat this for each four-byte chunk of an embedded x86-64 ELF that sets UID 0 and launches /bin/sh, then execute the target (default /usr/bin/su) to obtain root. The tools support --check-only, --target, --cleanup, and SIGINT/SIGTERM cleanup handling. The availability check only verifies AF_ALG/algorithm accessibility and does not independently prove exploitation behavior. copyfail_detect.sh compares buffered and direct-I/O hashes of setuid files, checks algif_aead state, and inspects suspicious root-shell lineage. copyfail_mitigate.sh assesses availability, supports disabling/blacklisting algif_aead, and can create a seccomp profile blocking AF_ALG socket creation in containers. No remote network exploitation or command-and-control endpoint is present; all exploit actions are local kernel, filesystem, process, and Unix-socket operations.
This repository is a compact standalone Python local privilege-escalation exploit for CVE-2026-31431 ('Copy Fail'). It contains one executable script, copy_fail_exp.py, plus a README and .gitignore. The exploit is not part of a larger framework and uses only Python standard-library modules plus ctypes to invoke the native splice() syscall. The script targets Linux kernel AF_ALG/splice page-cache corruption behavior. Its core routine creates an AF_ALG socket, binds it to the algorithm string authencesn(hmac(sha256),cbc(aes)), configures socket options, accepts an operation socket, and uses sendmsg plus two splice() calls to move data between a readable file descriptor and the AF_ALG socket. The target file is hardcoded as /usr/bin/su. A zlib-compressed payload blob is decompressed, then written in 4-byte chunks by repeatedly invoking the corruption primitive at increasing offsets. After patching the cached contents of the target SUID binary, the script executes su via os.system("su"), attempting to obtain elevated execution and a root shell. Repository structure is minimal: README.md explains the vulnerability, affected kernel ranges, requirements, and expected outcome; copy_fail_exp.py is the sole exploit implementation and likely entry point. There are no network C2 endpoints or remote targets. The only notable observables are the local file target (/usr/bin/su), the AF_ALG socket family and algorithm identifiers, and the external reference URLs in the README. Overall, this is an operational local LPE PoC with a built-in payload path rather than a detection script.
This repository contains two Python local privilege-escalation exploit scripts for CVE-2026-31431, labeled "Copy Fail." Both scripts abuse a vulnerable Linux kernel AF_ALG/algif_aead code path in combination with splice() to corrupt the page cache of a privileged executable. The exploit logic is operational rather than a mere PoC: it includes an embedded compressed payload, decompresses it, writes it into the target file's cached contents in 4-byte chunks, and then executes su to attempt privilege escalation. Repository structure: copy2.py is a compact/minified exploit variant using ctypes to call libc splice() directly as a compatibility polyfill. copyfail.py is the clearer, documented version with logging, helper functions, and constants. In copyfail.py, decode_payload() inflates the embedded zlib blob; overwrite_chunk() creates an AF_ALG socket, binds to the AEAD algorithm string authencesn(hmac(sha256),cbc(aes)), sets SOL_ALG socket options, sends crafted ancillary data, and uses os.splice() with a pipe to drive the vulnerable kernel path; patch_target() iterates over the payload in 4-byte chunks and overwrites the target page cache; main() runs the patching routine and then invokes su. Notable inconsistency: comments/docstrings mention overwriting /usr/bin/su, but the actual TARGET_BINARY constant and file open path are /usr/bin/passwd in both scripts. The final command executed is su. This suggests the exploit intends to patch one privileged binary and then leverage another privileged execution path, or the comments were not fully updated. No external network infrastructure, URLs, or C2 endpoints are present; the only "endpoints" are local file paths and Linux kernel AF_ALG crypto API identifiers. Overall, this is a local Linux kernel exploit designed to achieve privilege escalation by page-cache corruption of a SUID binary.
This repository is a small standalone local Linux exploit containing one Python script (passwd.py), a README, and a license. Its purpose is to change any local user's password without first spawning a root shell by chaining two vulnerabilities: CVE-2026-46333 to steal a readable file descriptor for /etc/shadow from the SUID chage utility, and CVE-2026-31431 (CopyFail) to convert that readable descriptor into a 4-byte arbitrary page-cache write primitive. The main exploit flow in passwd.py is: spawn /usr/bin/chage -l root repeatedly, obtain a pidfd for the child, brute-force duplicate candidate file descriptors with pidfd_getfd, identify the duplicated descriptor that resolves to /etc/shadow via /proc/self/fd/<n>, read shadow contents to locate the target user's entry, derive a new password hash using libcrypt.crypt while reusing the victim's existing salt, and overwrite the hash in /etc/shadow 4 bytes at a time using an AF_ALG authencesn(hmac(sha256),cbc(aes)) crypto socket and splice-based CopyFail logic. The script also includes cleanup/error handling for page-cache state and warns that the modification is temporary until reboot or cache clearing. Capabilities are limited to local post-authentication abuse: reading shadow hashes, selecting a username, and replacing that account's password hash in cache. There is no network C2, remote exploitation, persistence, or shell payload. Because the payload is a hardcoded credential modification workflow rather than a customizable framework module, the exploit is best classified as OPERATIONAL.
This repository is a Python FastMCP-based exploitation toolkit with a React/Vite web dashboard for CVE-2026-31431 ('Copy Fail'), presented as a Linux kernel local privilege escalation tester. It is not just a detector: it embeds and deploys a real Python exploit payload, supports remote execution over SSH, local script export, subnet scanning, and mitigation generation. The backend lives under src/copy_fail_mcp/ and is the operational core; the frontend under webapp/ provides a dashboard for target discovery, assessment, exploit execution, and safety/help content. Key backend structure: server.py exposes MCP tools such as cf_scan_network, cf_check_target, cf_run_exploit, cf_assess, cf_get_exploit_script, cf_exploit_local, and mitigation helpers. checker.py contains the embedded exploit payload as gzip+base64, decodes it at runtime, checks kernel/config state, and orchestrates exploit/mitigation actions. ssh_client.py handles async SSH connectivity with agent forwarding and username enumeration. scanner.py performs asynchronous TCP/22 scanning and SSH banner inspection to identify likely Linux hosts. transport.py provides stdio/HTTP MCP serving, defaulting to 127.0.0.1:10955/mcp. Exploit capability: the embedded Python payload uses AF_ALG sockets, authencesn, and splice() to obtain an arbitrary page-cache write primitive in 4-byte chunks. It includes an 'escalate' mode that reads /etc/passwd, creates /tmp/.passwd.bak, and rewrites the root entry in page cache to remove the password field, enabling 'su root' without a password. It also includes a generic 'write' mode for arbitrary file/offset/data page-cache corruption. The repository additionally documents /usr/bin/su corruption as the conceptual exploit path, but the actual embedded payload shown here directly targets /etc/passwd for escalation. Operationally, the tool can scan a /24 subnet for SSH hosts, connect to targets over SSH, upload or emit the exploit script, run assessment logic, and optionally apply mitigations by blacklisting algif_aead or adding initcall_blacklist=algif_aead_init. The webapp communicates with the backend over /mcp and proxies to http://127.0.0.1:10955. Test infrastructure under test/docker/ provides an SSH container for validating the deployment pipeline, though not the kernel exploit itself. Notable security observations: the repository includes a real test private key at test/docker/keys/id_test_rsa and a docker-compose test target exposed on localhost:10966. The project intentionally obfuscates the exploit payload with gzip+base64 to reduce AV signature hits. Overall, this is a weaponized exploit management interface around an embedded Python LPE payload, with both network discovery and exploitation workflow support.
This repository contains a single Python exploit script, exploit.py, implementing a local Linux privilege-escalation technique. The code is heavily minimized/obfuscated but clearly performs kernel-facing operations through AF_ALG crypto sockets (socket family 38) and uses sendmsg, setsockopt, accept, pipe, and splice to trigger vulnerable behavior in the kernel crypto subsystem. The script defines a helper to decode hex strings, a core function c(f,t,c) that creates and binds an AF_ALG AEAD socket to the algorithm string 'authencesn(hmac(sha256),cbc(aes))', configures socket options at level 279 ('SOL_ALG'), sends crafted ancillary data, and splices data from an open file descriptor into the accepted socket. It opens /usr/bin/su, decompresses a hardcoded zlib blob into exploit data, iterates over that data in 4-byte chunks, and repeatedly invokes the primitive against the su file. Finally, it executes 'su'. Overall purpose: overwrite or corrupt the setuid su binary via a kernel bug to gain root locally. There are no network endpoints, C2 addresses, or remote targets; the exploit is strictly local and operational, with a hardcoded payload path and target binary.
This repository is a small but fully functional Linux post-exploitation/cryptojacking toolkit rather than a simple PoC. It contains 6 files: a README, two top-level bash scripts (setup.sh and killservice.sh), and a kernel subdirectory with a Makefile, a DKMS installer script, and a C-based kernel module rootkit. The README also references additional binaries not included in the provided file list: getroot (the local privilege-escalation exploit for CVE-2026-31431), xrandom (renamed XMRig miner), and a packaged archive. Primary structure and purpose: - setup.sh is the main orchestrator and likely entry point. It decides whether it already has root privileges; if not, it attempts to use a bundled getroot helper to execute commands as root. In root mode it installs the miner to /opt/kernel-kd/xrandom, creates and enables a persistent systemd service at /etc/systemd/system/kernel-kd.service, runs kernel/install.sh to deploy the rootkit, then executes killservice.sh. In non-root mode it falls back to userland persistence by copying the miner into ~/.xrandom, creating a launcher script, and adding cron entries for @reboot and every minute. - kernel/install.sh installs the disguised kernel module intel_uncore_freq_aux using DKMS when available, or direct compilation otherwise. It establishes persistence through /etc/modules-load.d, /etc/modprobe.d, udev rules, and initramfs-related configuration files across multiple Linux distributions. It then loads the module live with modprobe/insmod. - kernel/stealth.c is the stealth component. It masquerades as an Intel uncore frequency driver but behaves like a rootkit: it hides module presence, filters process/file names matching hardcoded strings such as xrandom and masscan, creates a sysfs control interface under /sys/kernel/intel_uncore_freq, and tampers with procfs output to falsify CPU and memory usage so monitoring tools show lower utilization. - killservice.sh is a post-install hardening and competitor-eviction script. It checks whether common exposed services are listening publicly and, if so, stops/disables/masks them, blocks their ports with iptables/ip6tables/nftables, and chmods associated binaries to 000. It also kills and removes known miner/XMRig artifacts and related systemd units. Exploit capability assessment: - Initial access is described in the README as abuse of exposed Docker Engine API on TCP 2375 to launch a privileged container with host mounts and chroot into the host. - Local privilege escalation is delegated to the referenced getroot binary targeting CVE-2026-31431 on vulnerable Linux kernels. Although the binary itself is not present in the provided files, setup.sh clearly expects and invokes it. - Persistence is implemented both as root (systemd service plus kernel module autoload) and as userland (cron plus launcher script). - Stealth is substantial due to the kernel module’s hiding and procfs falsification. - Monetization is cryptomining via the renamed xrandom/XMRig payload. Overall, this is a real operational malware toolkit with exploit-assisted privilege escalation, persistence, stealth, and environment hardening, not merely a detector or documentation-only repository.
This repository is a real local privilege-escalation exploit implementation for CVE-2026-31431 ('Copy Fail'), plus a safer vulnerability checker and a minimal embedded payload. The repo structure is straightforward: the actual exploit logic lives in src/, while the large nolibc/ tree is a bundled tiny libc/syscall layer used to build small static cross-architecture binaries. The Makefile builds four artifacts: payload, exploit, exploit-passwd, and vulnerable. CI workflows compile static binaries for multiple architectures and libc modes. Core exploit capability: src/utils.c implements the shared primitive patch_chunk(), which uses Linux AF_ALG crypto sockets with the authencesn(hmac(sha256),cbc(aes)) AEAD template, sendmsg(), pipe(), and splice() to corrupt page-cache-backed file contents without modifying the on-disk inode. This is the heart of the Copy Fail technique. Main exploit path: src/exploit.c embeds a static ELF payload produced from src/payload.c and writes it into the page cache of a target file, defaulting to /usr/bin/su. After overwriting the cached image in 4-byte chunks, it executes su. Because the inode remains setuid-root while execution pulls mutated bytes from page cache, the payload runs with elevated privileges. The payload itself is simple and operational: setgid(0), setuid(0), then execve(/bin/sh). Alternate exploit path: src/exploit-passwd.c targets /etc/passwd instead of a setuid binary. It finds the current user's UID field, overwrites the cached UID digits with zeroes, and then runs su <user>. If authentication succeeds, su consults the corrupted cached passwd entry and yields a root shell. This variant is intended for environments where direct mutation of setuid binaries is harder but /etc/passwd remains readable. Detection/checker: src/vulnerable.c is not the main exploit but a legitimate non-destructive checker. It creates a local file named testfile, attempts the same page-cache mutation primitive against it, and checks whether the cached contents changed to 'vulnerable'. It exits 100 if vulnerable, 0 if not, 2 if AF_ALG support/template availability prevents determination. Notable endpoints/targets are entirely local: /usr/bin/su, /etc/passwd, /bin/sh, /proc/sys/vm/drop_caches, and the AF_ALG algorithm name authencesn(hmac(sha256),cbc(aes)). There are no C2, network beacons, or remote targets. This is a local Linux kernel LPE PoC with an included operational root-shell payload, not a framework module or a mere detector.
Single-file Python local privilege-escalation exploit. The script monkey-patches os.splice via ctypes to call libc splice directly, then uses Linux AF_ALG crypto sockets with the algorithm string `authencesn(hmac(sha256),cbc(aes))` to trigger a kernel-side vulnerability. It opens `/usr/bin/su`, decompresses an embedded binary blob, and writes it into the target file in 4-byte chunks through a crafted sendmsg/splice sequence. After the overwrite completes, it executes `su`, indicating the intended outcome is root/elevated access via a trojaned or attacker-controlled replacement su binary. There are no network indicators such as remote URLs or IPs; the exploit is purely local and Linux-specific. Repository structure is minimal: one Python entry-point file (`exploit.py`) containing all exploit logic, embedded payload data, and final execution step.
This repository contains a compact Go local privilege escalation exploit for CVE-2026-31431, plus a short README listing build instructions and claimed affected Linux distributions. The main file, CVE-2026-31431.go, is a standalone exploit with no external dependencies beyond Go's syscall/unsafe packages. The exploit logic is implemented in two functions: main() and exploit(). The exploit() function builds the kernel corruption primitive by creating an AF_ALG socket (family 38, SOCK_SEQPACKET), binding it to the AEAD crypto interface with algorithm string authencesn(hmac(sha256),cbc(aes)), setting key/auth parameters via setsockopt, accepting an operation socket, crafting control messages for sendmsg, and then using splice twice to move data between the target file descriptor, a pipe, and the AF_ALG socket. This sequence is intended to trigger page-cache corruption. A read drains the socket/pipe state, and the sockets are closed. The main() function opens /usr/bin/su read-only, defines an embedded minimal x86_64 ELF payload as raw bytes, and iteratively calls exploit() in 4-byte chunks to overwrite the page cache for /usr/bin/su. The embedded ELF contains code that performs setuid(0) and then execve("/bin/sh"). After patching, the program executes /usr/bin/su, expecting the setuid-root binary to run the attacker-controlled cached payload and return a root shell. There are no network callbacks, C2 addresses, or remote targets in the code. All activity is local to the host kernel and filesystem. The only concrete filesystem targets are /usr/bin/su and /bin/sh. The README describes the exploit as 'local privilege escalation / container escape' and lists many Linux distributions and versions as affected. Overall, this is an operational local Linux kernel exploit that weaponizes a kernel memory/page-cache corruption bug to hijack a privileged executable and obtain root.
Repository contains a small local Linux privilege/behavior-manipulation proof of concept centered on page-cache corruption/patching via AF_ALG sockets. There are 4 files total: two exploit implementations in C (exploit.c and a shorter exploit-simple.c), one benign demonstration target (test.c), and a short README with build/run instructions. The main exploit logic creates an AF_ALG socket, binds to the AEAD algorithm string 'authencesn(hmac(sha256),cbc(aes))', sets a dummy key, accepts an operation socket, opens a target file, aligns to the page boundary, sends 8 bytes of AAD, splices file data into the crypto socket, then performs a 4-byte pwrite at a user-chosen offset. The code comments claim this abuses a kernel bug to dirty/modify page cache so the running file behavior changes without changing the file on disk. The exploit is entirely local: no remote networking, C2, or external URLs/domains are present. The intended use is patching executable code, with examples showing how to locate a conditional jump using objdump and replace bytes to invert logic in the sample test program so it prints 'Access Granted' instead of 'Access Denied'. exploit.c is the fuller version with error handling, usage guidance, and explanatory comments; exploit-simple.c is a condensed variant of the same technique; test.c is only a toy binary used to demonstrate the patch effect.
This repository is a very small local privilege-escalation PoC consisting of one Python exploit script and a README. The main file, CVE-2026-31431.py, prints a banner, defines a small hex-decoding helper, and implements a core exploitation routine that creates an AF_ALG socket, binds it to the AEAD algorithm string authencesn(hmac(sha256),cbc(aes)), sets crafted socket options at SOL_ALG (numeric 279), accepts the operation socket, and uses sendmsg() ancillary data together with splice() to move attacker-controlled bytes into a target file descriptor. The script opens /usr/bin/su read-only, decompresses a hardcoded zlib blob into a payload, and iterates over that payload in 4-byte chunks, invoking the exploitation primitive repeatedly to corrupt/overwrite the su binary. After the overwrite loop, it executes su via os.system("su"). The exploit is clearly local-only: there are no network callbacks, remote URLs, or C2 endpoints. Its notable fingerprintable targets are the local file path /usr/bin/su and the Linux AF_ALG crypto interface identifiers used to trigger the bug. The README describes the issue as a copy-on-write/length-confusion flaw in the Linux kernel AF_ALG authencesn AEAD implementation and states that the PoC demonstrates arbitrary file corruption leading to root privilege escalation. Overall, this is an operational PoC with a built-in hardcoded payload rather than a detection script or framework module.
Repository contains a small standalone local privilege escalation exploit for CVE-2026-31431 ('Copy Fail') targeting the Linux kernel algif_aead AF_ALG interface. There are two Python exploit variants: one for x86_64 (CVE-2026-31431-x64.py) and one for Ubuntu 24.04 aarch64 (ubuntu24.04-aarch64.py), plus a README describing affected distributions and reproduction notes. Both scripts are nearly identical: they create an AF_ALG AEAD socket, bind it to the algorithm string 'authencesn(hmac(sha256),cbc(aes))', configure it with setsockopt/sendmsg control messages, and abuse splice/pipe interactions against an open handle to /usr/bin/su. A zlib-compressed embedded blob is decompressed and written in 4-byte chunks through repeated calls to helper function c(), suggesting architecture-specific replacement bytes for su. After the overwrite/corruption step, the script executes 'su' to obtain elevated privileges. No network communication, C2, or remote target endpoints are present; this is a purely local kernel LPE exploit. The code is concise and operational rather than framework-based, with hardcoded payload bytes and target path.
This repository is a compact Python local privilege escalation PoC for CVE-2026-31431 ('Copy Fail'). It contains one executable script, copy_fail_exp.py, plus a README and .gitignore. The exploit is not part of a larger framework. The Python script uses only standard-library modules (os, zlib, socket, ctypes). It creates an AF_ALG socket bound to the AEAD algorithm string authencesn(hmac(sha256),cbc(aes)), configures it with setsockopt, and uses ctypes to call the libc splice() syscall. The core routine repeatedly targets offsets in /usr/bin/su, sending crafted data through the AF_ALG socket and splicing file data through a pipe into the accepted socket. A zlib-compressed blob embedded in the script is decompressed and applied in 4-byte chunks, indicating the exploit patches the page cache contents of /usr/bin/su rather than editing the file conventionally. After patching, the script executes su to obtain elevated privileges. Repository structure is minimal and purpose-built: README.md explains the vulnerability, prerequisites, and intended outcome; copy_fail_exp.py is the sole exploit implementation and likely entry point. There are no network C2 endpoints, remote targets, or exfiltration logic. The exploit capability is strictly local: privilege escalation on a vulnerable Linux kernel with access to a readable privileged binary such as /usr/bin/su. The code appears operational rather than a mere detection script because it contains a full exploitation path and a concrete post-exploitation action (launching su for a root shell).
This repository is a minimal local privilege escalation exploit for CVE-2026-31431 ('Copy Fail'). It contains two files: a short Python exploit (exp.py) and a README describing usage and tested environment. The exploit is not network-facing and does not contact remote infrastructure; it is a local kernel exploit that abuses the Linux AF_ALG crypto socket interface together with splice/sendmsg behavior to corrupt file contents despite opening /etc/passwd read-only. The script defines a helper to decode hex, then a core function c(f,t,c) that creates an AF_ALG socket, binds to the AEAD algorithm string authencesn(hmac(sha256),cbc(aes)), sets socket options at level 279 (ALG_SET_* style options), accepts an operation socket, sends crafted ancillary data, and uses os.splice to move data between the passwd file descriptor, a pipe, and the accepted socket. In a loop, it writes 4-byte chunks from a zlib-compressed blob into successive offsets of /etc/passwd. The README explains that the decompressed blob contains the string 'root::0:0:', replacing the normal 'root:x:0:0:' prefix so root no longer requires a password. After patching, the script runs 'su', which should yield a root shell. Overall, this is a compact, functional LPE proof-of-concept with a hardcoded payload, making it operational rather than merely demonstrative.
This repository is a minimal local privilege escalation PoC for CVE-2026-31431 ('Copy Fail'). It contains one Python exploit script and a README. The script is heavily minified but functional: it determines the current username, reads /etc/passwd, locates the current user's passwd entry and specifically the UID field offset, opens /etc/passwd read-only, primes the file descriptor with a read, then creates an AF_ALG socket (family 38) bound to the AEAD transform 'authencesn(hmac(sha256),cbc(aes))'. It configures the crypto socket, accepts an operation socket, and uses sendmsg with crafted ancillary data plus splice() through a pipe to inject the bytes '0000' at the UID offset in the page cache view of /etc/passwd. After the in-memory overwrite, it calls 'su <username>'; because account lookup now sees UID 0 for that user, entering the user's normal password can yield a root shell. The exploit is local-only, targets Linux kernel AF_ALG behavior, and does not include remote networking or C2. Repository structure is simple: CopyFail_mini.py is the sole exploit entry point, while README.md explains the vulnerability, prerequisites, execution flow, and cleanup guidance. The exploit's main capability is volatile page-cache corruption of a read-only file to achieve root privilege escalation without persisting changes to disk.
This repository is a compact C implementation of a local Linux privilege-escalation exploit and detector for CVE-2026-31431 ('Copy Fail'). It is not part of a larger exploit framework. The project builds two binaries via the Makefile: bin/copy-fail-test for safe-ish vulnerability detection using a temporary sentinel file, and bin/copy-fail-exploit for actual exploitation. Repository structure: include/copy_fail.h defines constants, AF_ALG parameters, algorithm name, and function prototypes. include/su_payload_zlib.h contains a small zlib-compressed embedded payload. src/alg.c implements the core primitive: creating AF_ALG AEAD sockets, binding to authencesn(hmac(sha256),cbc(aes)), configuring control messages, and using splice() to trigger the vulnerable path that causes 4-byte writes into page cache. It exposes cf_theori_write4_fd() for arbitrary 4-byte chunk writes into the first 512 bytes of a target file's cached page and cf_trigger_sentinel() for detector use. src/util.c performs environmental prechecks, including AF_ALG availability, /proc/crypto presence, algorithm bindability, and simple LD_PRELOAD/ld.so.preload checks for AF_ALG-blocking shims. src/test_main.c creates a temporary file under /tmp, fills it with sentinel content, triggers the bug, rereads the page, and reports vulnerability based on marker insertion or byte differences. src/exploit_main.c is the main exploit entry point: it decompresses the embedded payload, opens /usr/bin/su read-only, warms the first page into cache, writes the payload into the cached image in 4-byte increments using cf_theori_write4_fd(), and finally execs /usr/bin/su. Main exploit capability: local privilege escalation on vulnerable Linux systems by corrupting the page cache of /usr/bin/su without modifying on-disk contents. The exploit relies on the AF_ALG AEAD + splice bug path and uses a hardcoded embedded payload, making it operational rather than merely demonstrative. No network communication, C2, or remote endpoints are present; the attack surface is entirely local kernel functionality and local filesystem targets.
This is a compact standalone local privilege escalation repository for CVE-2026-46333. It is not a framework module. The repo contains 5 files: a Makefile, README, headers, a D-Bus marshaling/payload file (dbus.c/dbus.h), and the main exploit (ptrace_may_dream.c). The Makefile builds a single binary, ptrace_may_dream, from ptrace_may_dream.c and dbus.c and links pthread, crypt, and util libraries. The exploit targets a Linux kernel race in ptrace_may_access() when mm == NULL during pidfd_getfd(2). The core idea is to race pidfd_getfd() against the exit of a privileged short-lived process so that ptrace access checks are skipped, allowing an unprivileged user to duplicate an open file descriptor from that process. Here, the chosen victim is accounts-daemon. The exploit searches /proc for the accounts-daemon PID, uses busctl to trigger activity in AccountsService, and specifically abuses SetIconFile to cause a short-lived child process. Multiple racing threads repeatedly call pidfd_getfd() against a guessed FD slot (default 5, matching the README note for dbus-broker) until one thread steals the D-Bus socket FD. Once the FD is stolen, the exploit writes a handcrafted D-Bus payload directly to that socket. dbus.c constructs three concatenated method calls on org.freedesktop.Accounts.User for the current user's object path: SetShell("/bin/bash"), SetAccountType(admin), and SetPassword(hash, ""). The password is hardcoded in dbus.h as pwned123 and hashed with crypt() using SHA-512 salt $6$xpl01t$. After sending the payload, the main program waits for accounts-daemon to apply the changes, verifies success by checking /etc/group for wheel membership and /etc/passwd for /bin/bash, then attempts to launch a root-capable shell path. Capabilities are therefore: local process enumeration, race-based FD theft via pidfd_getfd, direct D-Bus wire-format message construction, privilege escalation through AccountsService account modification, and post-exploitation shell access. There are no external network callbacks or C2 endpoints; all observables are local filesystem paths, procfs paths, D-Bus service/interface/object names, and external busctl invocations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1,642 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel vulnerability in crypto/algif_aead affecting the listed Google COS kernel packages. The fix removes complexity introduced for in-place operation, restores out-of-place operation, and copies associated data directly. The plugin rates the vulnerability High, lists available Core Impact and Metasploit exploits, and identifies a CISA Known Exploited Vulnerability remediation deadline. Update affected packages to version 19216.220.180 or later.
CopyFail is referenced as another Linux kernel exploit relevant to privilege escalation. Its CVE identifier appears in the linked repository URL; the content provides no mechanism, affected-version details, or evidence of real-world exploitation.
A Linux kernel vulnerability involving in-place operation in the algif_aead cryptographic interface. The fix reverts that behavior to out-of-place processing and simplifies associated-data copying. The advisory identifies affected Google kernel packages, available exploitation tools, and CISA Known Exploited Vulnerability status. It rates the vulnerability High, with CVSS v3 7.8 and CVSS v4 8.6, indicating potentially high confidentiality, integrity, and availability impacts from local exploitation.
A high-impact local vulnerability included in the CentOS/TuxCare advisory and used as its CVSS v3/v4 score source.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.