Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
-
Updated
Apr 29, 2026 - Python
Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated on Alibaba Cloud ACK, Amazon EKS and Google GKE.
Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)
CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback
Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).
Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation
Detection Only.. working on an exploit PoC
CopyFail (CVE-2026-31431): Linux kernel page-cache PrivEsc PoC + the only public detection tool. Novel PAM auth-bypass vector + Sigma/auditd/eBPF rules.
Copy Fail exploit (CVE-2026-31431) but in Rust.
Defense-in-depth primitives for CVE-2026-31431 (Copy Fail) — kernel detection probe and LD_PRELOAD AF_ALG block
Golang port of copy-fail-cve-2026-31431
Copy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.
Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.
CVE-2026-31431 Linux Local Privilege Escalation (LPE) Proof of Concept exploit
A defensive security toolkit specifically engineered to detect and mitigate CVE-2026-31431 and similar nftables / AF_ALG vulnerabilities. Includes non-destructive behavioral probes, module blacklisting automation, and Auditd/eBPF rules for real-time threat detection.
Copy Fail -- CVE-2026-31431 - Hardened AF_ALG/splice page-cache mutation primitive for RedTeam Ops.
Add a description, image, and links to the cve-2026-31431 topic page so that developers can more easily learn about it.
To associate your repository with the cve-2026-31431 topic, visit your repo's landing page and select "manage topics."