# theori-io/copy-fail-CVE-2026-31431

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

Repository: https://github.com/theori-io/copy-fail-CVE-2026-31431
Canonical: https://ross.abutalabs.com/products/copy-fail-cve-2026-31431
Homepage: https://xint.io/blog/copy-fail-linux-distributions
Language: Python
License Family: other
Topics: ai-security, cve-2026-31431, exploit, linux-kernel, privilege-escalation, privilege-escalation-exploits, security-research, theori, vulnerability, xint-code
Last push: 2026-04-29T21:21:46+00:00

## Health v2 (maintenance only)
Score: 50/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 79, release rhythm 35, longevity 9
- inputs: {"age_days": 126, "days_push": 126, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, young, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4049, forks 910 (observed 2026-08-28T04:08:33.820568+00:00)

## What it is
A proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation bug in the authencesn cryptographic template that allows a 4-byte page cache write. A 732-byte Python script corrupts a setuid binary's page cache to gain root on major Linux distributions.

## Use cases
- test if my Linux kernel is vulnerable to CVE-2026-31431
- demonstrate a local privilege escalation on Ubuntu or RHEL
- study a page cache corruption kernel exploit
- verify patching of the authencesn crypto template bug
- learn how AF_ALG and splice can be chained for exploitation
- reproduce a kernel LPE in a lab environment

## When to choose
- you need to validate whether your Linux hosts are exposed to CVE-2026-31431
- you are a security researcher studying kernel page cache exploits
- you are testing remediation in a controlled lab

## When to avoid
- you want a defensive scanning tool rather than an exploit PoC
- you are not authorized to test the target system
- you need a production-hardened tool with a license and support

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, vulnerability-scanning
- domain: security, operating-systems
- platform: python, cli
- tags: cve-2026-31431, lpe, privilege-escalation, linux-kernel, exploit, poc, security-research, page-cache, kernel-exploit, linux

## Member repositories
- theori-io/copy-fail-CVE-2026-31431 (main) score 50

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:33.820568+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:23:41.234847+00:00, confidence not recorded.
  - readme: https://github.com/theori-io/copy-fail-CVE-2026-31431 (fetched 2026-08-28T04:08:33.820568+00:00, sha f687b215df7f)
  - homepage: https://xint.io/blog/copy-fail-linux-distributions (fetched 2026-08-29T09:16:02.848219+00:00, sha 3bb27c06a23d)
  - site_page: https://xint.io/about-us (fetched 2026-08-29T09:16:02.851620+00:00, sha 0348ad00cfa9)
- Data as of 2026-08-30T08:39:29.467469+00:00.
