CVE-2026-31431 "Copy Fail": Linux algif_aead privilege escalation explained
A deterministic Linux kernel flaw, CVE-2026-31431 (CVSS 7.8), in crypto/algif_aead.c and authenc_esn.c lets a local user write 4 controlled bytes into the page cache of any readable file and gain root. Introduced in 2017, it affects kernels 4.14–6.18.21 and 6.19.11 and was patched in April 2026.
- CVSS 3.1 score 7.8 (HIGH): local privilege escalation and container escape
- Affects kernels 4.14–6.18.21 and 6.19.11, bug introduced in 2017
- Caused by a 2017 in-place optimization and authencesn writing past the auth tag
- Fix commit a664bf3d603d; found by Theori's Taeyang Lee
Read next
Security