DEV Community

yutianle
yutianle

Posted on

Copy Fail (CVE-2026-31431): 732 bytes from a low-privilege shell to root on Linux

Copy Fail (CVE-2026-31431): 732 bytes from a low-privilege shell to root on Linux

Local privilege escalation flaws have a narrower audience than remote ones, which is why they attract less attention. Copy Fail, tracked as CVE-2026-31431, was disclosed on 29 April 2026 and turns a modest local foothold into root on the major Linux distributions. Its relevance rests on a premise defenders often forget: any initial access that lands a normal user on a host is a few steps away from being an administrative compromise.

What the flaw is

The vulnerability is in the Linux kernel's AF_ALG cryptographic interface, specifically the algif_aead module that handles AEAD ciphers. The published research describes a four-byte controlled write into the page cache, combined with splice and the authencesn template, which is enough to modify data the kernel will later trust. The exploit is small, and the researchers' reference implementation is 732 bytes.
The score is CVSS 7.8, with a local attack vector. Affected kernels are those below 6.18.22, below 6.19.12, and below 7.0 depending on the release line. Fixed kernels are 6.18.22 or later, 6.19.12 or later, and 7.0 or later.

Why a local bug matters on shared and containerised hosts

Copy Fail does not cross a network boundary by itself, but it changes what a low-privilege execution point is worth. On a shared build runner, a CI container that runs untrusted code, or any multi-tenant host, the ability to escalate to root converts a contained process into control of the node and everything scheduled on it.
The kernel interface it abuses is not exotic. AF_ALG is present on ordinary systems, and the vulnerability is reached through code the attacker runs locally, which is exactly the position an attacker holds after a container breakout, a compromised dependency, or a foothold from a phishing payload.

What to do

Upgrade the kernel to a fixed release through the distribution package manager. Because the flaw is reached locally, patching effort should track where untrusted code already executes: container hosts, CI runners and machines with many users come first.
Kernel patches usually need a reboot, so teams that defer reboots are effectively unpatched. Track the kernel version actually running rather than the one that was installed, and treat a pending kernel update as an open finding.

References

Top comments (0)