By NHI Mgmt Group Editorial TeamBased on Orca Security: “Linux Kernel Bug (Copy.Fail) Enables Local Privilege Escalation to Root (CVE-2026-31431)” (April 30, 2026)

TL;DR: CVE-2026-31431, dubbed Copy Fail, lets an unprivileged local user gain root by corrupting the page cache of readable files without modifying the disk file, so normal integrity checks may miss exploitation, according to Orca Security. The issue shows how kernel-level privilege paths can bypass assumptions that remediation can be verified from the file system alone.


At a glance

What this is: This is a Linux kernel vulnerability analysis showing that page cache corruption through the AF_ALG AEAD in-place path can let a local user escalate to root without modifying the underlying file.

Why it matters: It matters because security teams may miss exploitation if they rely on file-integrity checks alone, and the problem affects kernel-level trust boundaries that sit below normal IAM and endpoint controls.

By the numbers:

  • The researchers tested exploitation on Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 14.3, and SUSE 16 across kernel lines 6.12–6.18.

Context

Copy Fail is a Linux kernel privilege-escalation flaw, not an application bug. It matters to identity and access teams because the attack turns a low-privilege local session into root by abusing kernel file-handling and crypto plumbing, which means the control failure sits below the layers many programmes monitor first.

The key governance problem is that the disk file remains unchanged while the page cache is corrupted. That breaks the assumption that integrity verification on the filesystem alone can confirm whether a system has been tampered with. For teams running Linux workloads, the identity lesson is that privileged execution paths can exist outside traditional account governance.


Key questions

Q: What breaks when a Linux local exploit can alter the page cache instead of the file on disk?

A: The usual assumption that file integrity tools and on-disk monitoring will catch the change breaks down. Attackers can manipulate what a process reads in memory, then use that altered state to elevate privileges without leaving the same footprint as a classic file replacement attack. That is why cache-aware root escalation is so dangerous.

Q: Why does a local kernel exploit matter to broader access governance?

A: Because local privilege escalation can bypass the assumptions behind least privilege, emergency access, and host trust. Once a low-privilege user can become root inside the kernel boundary, every downstream control that depends on the host being trustworthy becomes less reliable. The question is not just who logged in, but whether the execution layer can be trusted.

Q: What signs suggest AF_ALG-based privilege escalation may be possible on a Linux host?

A: Look for vulnerable kernel versions, exposed AF_ALG usage, and systems where local users or container workloads can reach kernel crypto interfaces. If the platform relies on filesystem checks while the kernel path remains unpatched, the host is still exposed even when files appear intact. Exposure context matters more than the visible state of a single binary.

Q: Should teams patch first or apply temporary AF_ALG restrictions first?

A: Patch first whenever possible, because blocking AF_ALG AEAD only reduces immediate exposure and does not remove the underlying kernel flaw. If patching is delayed, temporary restrictions should be used to narrow the attack path until the fixed kernel is deployed. The right choice depends on whether the host can be upgraded without operational risk.


Technical breakdown

How AF_ALG AEAD and splice() create a writable kernel path

AF_ALG exposes kernel cryptographic algorithms to userspace, while splice() can move page-cache-backed file pages by reference instead of copying them. In the vulnerable path, the authencesn AEAD template performed in-place decryption on data that originated from readable file pages. That combination turns a read-only source into a writable destination scatterlist, which is why a local attacker can influence kernel-managed memory associated with a legitimate file without changing the on-disk object. The exploit is therefore about memory handling in the kernel, not file replacement on disk.

Practical implication: validate kernel crypto interfaces and in-place data paths as part of hardening, not just file permissions.

Why page cache corruption can bypass file-integrity checks

Page cache holds in-memory copies of file data used for performance. If an attacker corrupts those cached pages while the underlying file stays unchanged, traditional integrity controls that compare disk content may see a clean file and miss the active compromise. That creates a visibility gap between persistent state and runtime state. The kernel can then execute or serve altered content from memory even though the filesystem appears intact, which is why post-exploitation detection must consider runtime memory and cache behaviour, not only hash baselines on disk artifacts.

Practical implication: correlate file-integrity results with runtime telemetry and kernel-state inspection before declaring an asset clean.

Why the AF_ALG AEAD in-place path matters for privilege escalation

The vulnerable AF_ALG AEAD in-place path is the bridge from low privilege to root. Because the page cache is shared and the path operates inside the kernel, the attacker does not need conventional write access to replace the binary on disk. The issue affects a broad set of Linux distributions and may extend into containers because they inherit the shared kernel boundary. That makes the problem a kernel trust issue, not a distro-specific application flaw, and it explains why patching the kernel is the decisive fix.

Practical implication: prioritise patched kernels and temporary blocking of AF_ALG AEAD where immediate upgrade is not possible.


Threat narrative

Attacker objective: The attacker aims to convert local, unprivileged access into root control of the Linux host without altering the on-disk binary.

  1. Entry occurs when an unprivileged local user reaches the vulnerable AF_ALG AEAD path through userspace access to kernel crypto interfaces.
  2. Escalation happens when splice() feeds page-cache-backed file pages into the in-place decryption flow and the writable scatterlist corrupts cached file data.
  3. Impact is root-level privilege on the host while the underlying disk file remains unchanged, which can conceal the compromise from normal integrity checks.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Runtime kernel state is now part of identity assurance: this vulnerability shows that trust in a Linux host cannot stop at file ownership, permissions, or disk hashes. The compromised object is the page cache, not the file itself, so the control failure sits in runtime state that many governance programmes do not inspect. Practitioners should treat kernel-managed execution paths as part of the identity assurance surface, not as an implementation detail.

Filesystem integrity is an incomplete control for privilege-boundary validation: the disk copy can remain unchanged while the active memory representation is corrupted. That means a successful attack can survive a clean-looking file system and still deliver root. The broader lesson is that security assurance needs runtime corroboration when kernel features can separate persistent content from executable state.

AF_ALG AEAD in-place handling creates a control assumption that the kernel itself can safely transform shared file pages: that assumption fails when userspace can steer readable pages into a writable destination scatterlist through splice(). The implication is that kernel crypto interfaces used from unprivileged contexts need governance as privileged attack surface, not just code-level review.

Copy Fail is an example of identity blast-radius inflation at the kernel layer: a single local user can move from unprivileged access to root without touching the usual access-control chain. That broadens the blast radius from one account to the entire host and can extend into containers that share the kernel. Practitioners should treat kernel privilege paths as part of platform identity governance, not only vulnerability management.

Kernel trust boundaries need to be reasoned about like privileged workflows, not static assets: this issue shows that a readable file can become a source of writable influence when the kernel mixes crypto, I/O, and caching semantics. The practical consequence is that remediation, containment, and verification must all account for runtime kernel behaviour, because file-state alone is not enough to establish control.

From our research library:

What this signals

Copy Fail shifts attention from file integrity to runtime integrity: security teams should treat kernel-managed memory, crypto paths, and page cache behaviour as first-class verification targets when assessing Linux hosts. A clean hash no longer proves that the execution environment is trustworthy.

Kernel privilege paths deserve the same governance discipline as privileged accounts: when a local user can cross into root through AF_ALG AEAD and splice(), the host has an identity boundary problem, not just a patching problem. That pushes remediation decisions toward runtime context, host criticality, and exposure, rather than generic vulnerability queues.


For practitioners

  • Patch vulnerable kernels first Move exposed hosts to a fixed kernel version before relying on any compensating control. Prioritise systems running Linux distributions and kernel lines confirmed by the advisory, especially where local user access exists.
  • Block AF_ALG AEAD where upgrade is delayed Use temporary mitigations such as blacklisting algif_aead or restricting AF_ALG sockets with seccomp until patching is complete. Treat this as an interim containment measure, not a full remediation.
  • Search for runtime exposure, not only file changes Validate whether affected hosts are internet accessible, runtime reachable, or critical before scheduling remediation. The risk is driven by exploitable kernel paths, so asset context should guide the order of work.
  • Assume clean hashes do not clear the host Do not treat unchanged disk files as proof that Copy Fail was not exploited. Pair integrity checks with runtime investigation of kernel behaviour and privileged execution paths.

Key takeaways

  • Copy Fail shows that a Linux host can be compromised through page cache corruption even when the on-disk file is unchanged.
  • The article cites exploitation testing across Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 14.3, SUSE 16, and kernel lines 6.12–6.18.
  • The decisive response is to patch the kernel and use temporary AF_ALG restrictions only as a short-lived containment measure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0004; TA0006 — Privilege Escalation; Credential AccessThe article centers on local privilege escalation through a kernel flaw.
Recommendation — Map the exploit path to privilege escalation and prioritise detection around local-to-root transitions.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe flaw defeats the expectation that low-privilege users cannot reach root-level execution.
Recommendation — Apply least-privilege controls to reduce the blast radius of any local user session.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe issue undermines host authorization assumptions below the application layer.
Recommendation — Review authorization boundaries on Linux workloads and verify that privileged paths are constrained.
CIS Controls v8CIS-5 — Account ManagementAccount management is relevant because the exploit turns an unprivileged account into root access.
Recommendation — Harden account handling on Linux hosts and monitor for unexpected privilege transitions.

Key terms

  • Page-cache corruption: A memory corruption pattern where data held in the kernel page cache is altered in place instead of being changed on disk. In Linux escalation cases, this matters because the attacker can influence what the system executes or trusts without leaving a normal file-modification trail.
  • In-place Decryption: In-place decryption is a processing pattern where decrypted output is written back into the same buffer or storage location used for input. In kernel paths this can be dangerous when shared or page-cache-backed data is treated as writable, because the transformation may affect runtime state without changing the underlying file.
  • AF_ALG: AF_ALG is a Linux kernel interface that exposes cryptographic algorithms to userspace. When it is used in vulnerable paths, it can become part of a privilege-escalation chain rather than a simple service interface, especially when kernel memory handling is unsafe.
  • Privilege Escalation: An attack technique where a compromised identity, often an NHI with initially limited permissions, exploits vulnerabilities or misconfigurations to gain elevated access rights, typically leading to broader compromise.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org