What happened
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Affected versions
Kernel: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · Liverwortenuresis371/copyfail-rsExploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.LPERustHIGHAnalyzed★ 0⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: af-alg, auditd, copyfail, cve, cve-2026-31431, detection-engineering, ebpf, local-privilege-escalationLiverwortenuresis3712026-05-05CandidateCVE-Intel · theori-io/copy-fail-CVE-2026-31431Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint CodeLPEPythonHIGHAnalyzed★ 4050⑂ 910EPSS 99.91%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: ai-security, cve-2026-31431, exploit, linux-kernel, privilege-escalation, privilege-escalation-exploits, security-research, theoritheori-io2026-04-29CandidateCVE-Intel · iss4cf0ng/CVE-2026-31431-Linux-Copy-FailRust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).LPERustHIGHAnalyzed★ 56⑂ 21EPSS 99.91%CVE data: CNACode indexedUpdated 25 Aug 2026Tags: cve, cve-2026-31431, exploit, explotation, linux, linux-vulnerability, poc, privilege-escalationiss4cf0ng2026-04-30CandidateCVE-Intel · EynaExp/Copy-Fail-CVE-2026-31431-modernizedA modernized version of Copy Fail PEExploitPythonHIGHAnalyzed★ 3⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 25 Aug 2026EynaExp2026-05-02CandidateCVE-Intel · Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-FailExploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.LPERustHIGHAnalyzed★ 3⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 25 Aug 2026Tags: af-alg, container-security, copy-fail, cve-2026-31431, educational, explotation, kernel-exploit, linux-vulnerabilityDullpurple-sloop7262026-05-06CandidateCVE-Intel · painoob/Copy-Fail-Exploit-CVE-2026-31431Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution shipped since 2017.ExploitPythonHIGHAnalyzed★ 104⑂ 22EPSS 99.91%CVE data: CNACode indexedUpdated 24 Aug 2026painoob2026-04-29CandidateCVE-Intel · 6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284ExploitCHIGHAnalyzed★ 1⑂ 0EPSS 99.91%CVE data: CNACode indexedUpdated 24 Aug 20266abc2026-05-05CandidateCVE-Intel · xeloxa/copyfail-exploitCopy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.LPEPythonHIGHAnalyzed★ 24⑂ 4EPSS 99.91%CVE data: CNACode indexedUpdated 24 Aug 2026Tags: af-alg, copy-fail, cve-2026-31431, exploit, linux-kernel, lpe, privilege-escalation, security-researchxeloxa2026-05-04CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.