logo

Copy Fail: Public PoC and Full Details Disclosed for the 732-Byte Linux Root Exploit (CVE-2026-31431)

ID: defc863b-e278-5276-8a06-ef97ac0fb626

STIX ID: report--defc863b-e278-5276-8a06-ef97ac0fb626

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-30

Author: Ddos

...
...

**Copy Fail (CVE-2026-31431):** A critical logic bug in the Linux kernel's AF_ALG AEAD implementation allows an unprivileged local attacker to perform a deterministic 4-byte write into the page cache of any readable file, enabling trivial setuid binary tampering and immediate root escalation; the proof-of-concept and full technical details are public, many distributions are affected since 2017, and administrators are advised to apply vendor patches or mitigate by blocking AF_ALG sockets (e.g., via seccomp).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.