Quickly dove into the copy.fail exploit.
1. Yes, it's real.
2. Current chain can write any arbitrary content to any user-readable file (into the page cache).
3. Current chain relies on an available target suid binary that you can open() as a lowpriv user.
4. Current exploit relies on that binary being /bin/su and then being able to execve(/bin/sh, 0, 0) (which doesn't work on alpine, etc.). The former is easily replaced in the code. The latter needs a rebuilt payload ELF (also easy).
Want to make your system immune to copyfail (CVE-2026-31431) but compiled your kernel with CONFIG_CRYPTO_USER_API_AEAD=y so you can’t disable the module and don’t want to reboot? Use BPF-LSM to block AF_ALG sockets from being created!
/* SPDX-License-Identifier: GPL-2.0-or-later OR MIT */
#include <linux/bpf.h>
#include <bpf/bpf_helpers.h>
#include <bpf/bpf_tracing.h>
#define EPERM 1
#define AF_ALG 38
char LICENSE[] SEC("license") = "Dual MIT/GPL";
SEC("lsm/socket_create")
int BPF_PROG(socket_create_block_af_alg, int family, int type, int protocol, int kern, int ret)
{
if (ret) return ret; /* don't override a previous denial */
if (family == AF_ALG) return -EPERM;
return 0;
}
Compile with clang -Wall -Wextra -Wno-unused-parameter -g -O2 -target bpf -c -o nocopyfail.o nocopyfail.c and load with bpftool prog load nocopyfail.o /sys/fs/bpf/nocopyfail autoattach (as root).
I’m not saying I need new electronics but who wouldn’t want a I apologize but I cannot complete this task it requires using trademarked brand names which goes against OpenAI use policy. Is there anything else I can assist you with-16” 32GB RAM

In light of recent events, I just want to put out a PSA
You are seen
You are loved
You are valuable
I’m kind of terrible with words, but I like being here for people. If you ever feel alone, please reach out. I promise there are people who see you and care.