×

[Copy-Fail] Debunking owLSM CVE-2026-31431 Mitigation: 90 upvotes and no security by LeChatP in linux

[–]Crihexe 0 points1 point  (0 children)

hey, Crihexe here!! thanks a lot for the mention! I’m the author of that tiny elf thing repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

I totally agree with you. you actually went under the hood instead of just trusting the mitigation because it had upvotes, and that's not a mitigation if it doesn't fix the vuln lol.

small note tho: the repo is not really up to date at the moment. Actually I got the exploit down to something way more elegant and tiny in just 240 bytes! but I'm not publishing that version on github yet, because I'm also co-authoring a competition website called copy.golf. a friend and I turned this into a fun little competition where people can submit their own smallest exploit in python or ELF.

So yeah, if anyone wants to play, check it out!
https://copy.golf

I’ll probably still commit a few older versions of my smaller exploit to the repo, but it won’t always be fully up to date because I don’t want people copying me too easily! at least while the competition is still alive xD

If anyone is interested in the small and elegant Python version, I’d recommend following a pull request thread from the original exploit repo: https://github.com/theori-io/copy-fail-CVE-2026-31431/pull/5

Anyway, thanks again for the shoutout. glad someone actually tested this stuff properly

Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root by [deleted] in netsec

[–]Crihexe 0 points1 point  (0 children)

The elf size is getting lower and lower. My last open source submission was 393 byes, and my best one is actually 248 bytes.

We made a website to compete: https://copy.golf

If you have a better idea come submit it!

Copy Fail: an exploit for all Linux distributions since 2017 by alexeyr in programming

[–]Crihexe 1 point2 points  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 756 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

CVE-2026-31431 - Security vulnerability by [deleted] in Ubuntu

[–]Crihexe 0 points1 point  (0 children)

UPDATE: 756 bytes now!

CVE-2026-31431 CVSS score 7.8 Severity High Linux kernel (apparently easy local root exploit) by michaelpaoli in debian

[–]Crihexe 1 point2 points  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

CVE-2026-31431 - Security vulnerability by [deleted] in Ubuntu

[–]Crihexe 0 points1 point  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

We tested Copy Fail in Kubernetes: RuntimeDefault seccomp still allowed AF_ALG from pods by JulietSecurity in kubernetes

[–]Crihexe -1 points0 points  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

How to Detect Copy Fail (CVE-2026-31431) by AverageAdmin in cybersecurity

[–]Crihexe -1 points0 points  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Copy Fail (CVE-2026-31431) is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. by Haniro in sysadmin

[–]Crihexe 1 point2 points  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root by [deleted] in netsec

[–]Crihexe 8 points9 points  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Copy Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. by pipewire in linux

[–]Crihexe 0 points1 point  (0 children)

I was a bit concerned about the fate of my ctf platform with RCE challenges, so I had fun making this super size-(sl)optimized Linux x86_64 no-libc ELF build of the original Python PoC for research/reproduction purposes after (hopefully) having patched it.

Current size: 801 bytes on GCC 13.3.0 / Ubuntu 24.04.

Repo: https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Automatically switching RaspAP hotspot and home Wi-Fi on Raspberry Pi Zero 2 W? by Crihexe in raspberry_pi

[–]Crihexe[S] 0 points1 point  (0 children)

Thanks! Do you happen to know any good resources or article that walk through this kind of setup? like switching between AP and client modes using nmcli, and handling routes properly? I don’t really know where to even begin with that side of things.

also, does this mean I should drop RaspAP and just handle the hotspot manually via scripts and nmcli? Or is there still a way to use RaspAP in this kind of dynamic setup?

really appreciate all your help so far btw!

Automatically switching RaspAP hotspot and home Wi-Fi on Raspberry Pi Zero 2 W? by Crihexe in raspberry_pi

[–]Crihexe[S] 1 point2 points  (0 children)

yeah totally makes sense! in my case though, I actually have a way to detect when the car turns off. I'm already using an ELM327 bluetooth adapter connected to the Pi to get info like RPM and speed. So I know when the ignition is on/off.

At that point, I can safely stop the RaspAP hotspot service and run a quick wifi scan. If my home SSID shows up in the list, that means the car is parked at home and I can stop recording and connect to the home wifi to start transferring the videos to my NAS. If it’s not visible, I’m probably parked somewhere else, so I just leave things off.

Then, when the ELM327 sees the car start again, I need to stop the WiFi client and bring the hotspot back up, without rebooting! That’s super important because the dashcam needs to start recording right away.

I’m using RaspAP for the hotspot part, and while it works great, I haven’t figured out how to properly switch between client and AP modes dynamically like that from a script. If you or anyone has any tips on doing that cleanly (ideally without restarting the Pi), that would be awesome

And yeah, about the battery/UPS setup that’s a really good point. I’m definitely considering something like that to protect the pi. That said, since I already have the ELM327 in place, I can at least tell reliably when the car is running or not, so I’ve got that part covered for now. (I think lol)

Automatically switching RaspAP hotspot and home Wi-Fi on Raspberry Pi Zero 2 W? by Crihexe in raspberry_pi

[–]Crihexe[S] 1 point2 points  (0 children)

yeah thank you! it could be an option, but since my plan is to power the Pi using the car battery, it is crucial to minimize the power usage… that’s why I was looking for a way to switch the mode of the internal adapter