discovered 03 Aug 2026
CVE-2026-31431-CopyFail-Universal-LPE
→ View on GitHubCVE-2026-31431-CopyFail is a local privilege escalation exploit targeting a vulnerability in the Linux kernel's AF_ALG crypto subsystem, allowing an unprivileged user to perform a 4-byte arbitrary write in the kernel's page cache. The tool offers multiple exploitation methods, including dynamic ELF entry point overwrites and full binary replacements, with compatibility for both Python 2 and 3. Notable features include determinism without race conditions, operation within default Docker containers, and independence from kernel version, making it applicable across all kernels since 2017.