CVE-2026-31431: 732-byte exploit grants root on Linux
The Copy Fail flaw (CVE-2026-31431) in the Linux kernel's algif_aead module lets a local attacker escalate to root via a four-byte write into the page cache through AF_ALG. CVSS is 7.8 and the reference exploit is 732 bytes. Kernels below 6.18.22, 6.19.12 and 7.0 are affected.
- Flaw in the Linux kernel algif_aead module, CVSS 7.8, local attack vector
- Exploit is 732 bytes, uses splice and the authencesn template
- Affected kernels: below 6.18.22, 6.19.12 and 7.0
- Fixed in 6.18.22, 6.19.12 and 7.0 or later
Read next
Security