CVE-2026-31431

high

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

References

https://github.com/silentbyte69/copy-fail-CVE-2026-31431-cpp

https://github.com/Daya0x7F0X/cve-research-lab

https://github.com/Hz-zH299/cve-reproduce-reports

https://github.com/thesungod07/CVE-List

https://github.com/HackSpeak/linux-lpe-2026

https://github.com/joaocalciolari07/copyfail-guard

https://github.com/bingyu-83/cve-feishu-bot

https://github.com/pullrun/pullrun

https://github.com/bahartanir/wp2shell-scanner

https://github.com/the-artist111/NeuralReaper

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/OleksandrBlack/cve_centos

https://github.com/Tinnci/cve-2024-31317

https://github.com/Quaerendir/linux-pagecache-cve-audit

https://github.com/Quaerendir/cve-2026-46331-audit

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/qux-bbb/CVE_exp

https://github.com/vk-cs/linux-cve-checker

https://github.com/MillerDetach/poc-lab-pro

https://github.com/liamromanis101/k8s-container-escape-audit-lite

https://github.com/SmashMythAmp/poc-lab-605

https://github.com/antinest/CVEs

https://github.com/1neptune/CopyFail

https://github.com/attaattaatta/cve_2026_frag_family_fix

https://github.com/vishvacyber/Detection-Tool-Kit-for-CVE-2026-31431

https://github.com/rain-fly/linux-privesc-cves

https://github.com/Jacob-xiaoping/CVE

https://github.com/huuvehcie/Copy-Fail-CVEs

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/InnerWarden/innerwarden-lab

https://github.com/ridhinva/copyfail-checker

https://github.com/nb-dog/cves

https://github.com/waltrone1/copyfail-safe-check

https://github.com/krislamo/vulnlab

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/PandaInRed/redos-kernel-cve-patches

https://github.com/yangh-beep/CVE-2026-31431-C

https://github.com/sgkdev/ptrace_may_dream

https://github.com/GubiczaP/cve-2026-31431-checker

https://github.com/cj667113/OCI-Ansible-Fix-CVE-2026-31431

https://github.com/First-John/cve_2026_frag_family_fix

https://github.com/First-John/CVE-2026-43500

https://github.com/Yakovyakov/cve-2026-31431-mitigation

https://github.com/Ruby570bocadito/CVE-ubuntu-server-24.04

https://github.com/fearlessresponsesolution/cve-pocs

https://github.com/royayub/CVE-2026-31431

https://github.com/hershate/CVE-Lookup-skill

https://github.com/insomnisec/public_cve_detections

https://github.com/Pithase/asm-copyfail

https://github.com/Aurillium/public-passwd

https://github.com/Maxime288/CVE-2026-31431-Copy-Fail-R-pertoire-de-Pr-vention

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/barmi/cve-patch-auditor

https://github.com/xd20111/CVE-2026-43284

https://github.com/PR1N5/CVEVault

https://github.com/dotPY-hax/CopyFail

https://github.com/adibirzu/oci-emergency-patcher

https://github.com/rituraj-dubey/Exploit-POC

https://github.com/Sebastian294/cve-2026-31431

https://github.com/Carlys17/security-scripts

https://github.com/SilverRuler/copy-fail-CVE-2026-31431

https://github.com/thawfeer/exploits

https://github.com/DroPZsec/SplicePrivillegeEscalationFIX

https://github.com/paulorlima9/copyfail-fix

https://github.com/studiogangster/CVE-2026-31431

https://github.com/gbonacini/CVE-2026-31431

https://github.com/polyakovavv/copyfail

https://github.com/dgrobinson0/CopyFile_CVE-2026-31431

https://github.com/blamejs/exceptd-skills

https://github.com/mauricioportela/CVE-2026-31431-Analysis

https://github.com/MaxMerdes/Linux-Kernel-CVE

https://github.com/vorkampfer/copyfail2_electric_boogaloo_fix

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/h1994st/cairn

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/haydenjames/dirty-frag-check

https://github.com/tuapuikia/linux-security-mitigation

https://github.com/Helios973/CVE-2026-31431_exp.c

https://github.com/Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cache-lpe

https://github.com/vorkampfer/copy_fail_mitigation

https://github.com/finwo/cve-toolkit

https://github.com/krisiasty/vcheck

https://github.com/hori0729/CVE-2026-31431-Verificador-Exploit

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/yifengzis/CVE

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/dixyes/dirtypatch

https://github.com/p401a-ops/Copy-Fail

https://github.com/OpenPixelSystems/c-copy-fail

https://github.com/Morton-Li/copy-fail-CVE-2026-31431

https://github.com/CyberZik/CVE-RESEARCH

https://github.com/hyeonjunjo24/CVE-2026-31431-_Copy-Fail

https://github.com/insomnisec/Detections-CVE-2026-23918

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/mk4me/lpe-audit-kit

https://github.com/ClimbMunchkin/fix-cve-2026-3143

https://github.com/julichaan/CVE-2026-31431-python-copyfail-POC

https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix

https://github.com/Tecnotec-CL/CVE-2026

https://github.com/tang-yikai/copy-fail-mitigation-with-bpftrace

https://github.com/pvpaulo01/cve-2026-31431

https://github.com/kw-soft/copyfail

https://github.com/Vatson112/deny-af-alg-bpf

https://github.com/361way/CVE-2026-31431

https://github.com/Mr-bv/Copy-fail-CVE-2026-31431-Exploit-in-C

https://github.com/0xploitNinja/Detection-Rules

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/ikow/CVE-2026-31431-live-code-corruption

https://github.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2026-31431-CopyFail

https://github.com/StarxSky/CVE-2026-31431

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/grabesec/XCP_ng_CVE-2026-31431_tester

https://github.com/0xN7y/CVE-2026-31431

https://github.com/tangjie1/CVE-2026-31431-Check

https://github.com/luoqianlin/copyfail-c

https://github.com/voxcia-io/copy-fail

https://github.com/OneDemobird/copy-fail-CVE-2026-31431-pythonlower3.10

https://github.com/sgkdev/page_inject

Details

Source: Mitre, NVD

Published: 2026-04-22

Updated: 2026-09-08

Named Vulnerability: copy.failNamed Vulnerability: CopyFailNamed Vulnerability: Copy FailKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 8.6

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.99907

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest