cevrixa, Local Privilege Escalation, CVE-2026-31431 (High) -DC-Oct2026-2757

Listen to this Post

CVE-2026-31431 is a Linux kernel vulnerability in the `algif_aead` / `authencesn` AEAD implementation that allows a local attacker to escalate privileges to root. The flaw resides in the out-of-place operation revert logic within the AEAD subsystem, where improper handling of the scatterlist during the `authencesn` template processing leads to a use-after-free condition. When an attacker triggers the vulnerable path, the kernel fails to correctly copy the authentication tag back to the user-supplied buffer, leaving stale pointers in the page cache. This enables the attacker to corrupt the page cache of a privileged executable, such as /usr/bin/su, by overwriting its code with shellcode. The exploit works because the kernel does not validate the integrity of the page cache after the AEAD operation completes, allowing the injected payload to execute with root privileges when the binary is invoked. The vulnerability affects all versions of the cevrixa platform prior to v1.0.0, as the platform bundles a Linux kernel module that exposes the vulnerable `algif_aead` interface to unprivileged users. An attacker with local access can compile and run the exploit, which first opens an AF_ALG socket, binds to the `authencesn(hmac(sha256),cbc(aes))` algorithm, and then crafts a sequence of `sendmsg` and `recvmsg` calls to manipulate the scatterlist. By carefully controlling the input and output buffers, the attacker forces the kernel to revert the operation out-of-place, causing the page cache page for `/usr/bin/su` to be replaced with attacker-controlled data. Once the page cache is corrupted, the attacker simply executes `su` with a known password or triggers a passwordless path, and the injected shellcode spawns a root shell. The exploit is reliable on x86_64 architectures with the `CONFIG_CRYPTO_USER_API_AEAD` option enabled, which is the default in most distributions. The cevrixa platform inherits this vulnerability because its container runtime does not restrict the AF_ALG socket family, allowing unprivileged processes to access the cryptographic API. The vulnerability was discovered by security researchers at NOMISEC, who published a proof-of-concept exploit on the Lutfifakee-Project repository. The exploit requires no special privileges beyond a standard user account and can be executed in a few seconds. The root cause is a missing check in the `aead_recvmsg` function, where the `crypto_aead_decrypt` call returns `-EINPROGRESS` and the subsequent revert operation mishandles the `src` and `dst` scatterlists. This leads to a situation where the destination buffer is not properly updated, and the original page cache page remains mapped in the kernel’s address space. The attacker leverages this to write arbitrary data to the page cache by using the `splice` system call to pipe data from the AF_ALG socket to the target file. The vulnerability is particularly dangerous because it bypasses many container isolation mechanisms, allowing a compromised container to escape and gain root on the host. The cevrixa platform’s default configuration does not block the `AF_ALG` socket, making it exploitable out of the box. The CVE was assigned a CVSS score of 7.8 (High) due to the local attack vector and the high impact on confidentiality, integrity, and availability.

DailyCVE Form:

Platform: cevrixa
Version: 1.0.0
Vulnerability: LPE algif_aead
Severity: High
date: 2026-03-15

Prediction: 2026-04-15

What Undercode Say:

Check if AF_ALG is available
ls /proc/crypto | grep authencesn
Compile the exploit
gcc -o cevrixa_lpe cevrixa_lpe.c -lpthread
Run the exploit
./cevrixa_lpe
Verify root shell
id
// cevrixa_lpe.c - Simplified PoC for CVE-2026-31431
define _GNU_SOURCE
include <stdio.h>
include <stdlib.h>
include <string.h>
include <unistd.h>
include <fcntl.h>
include <sys/socket.h>
include <linux/if_alg.h>
include <sys/uio.h>
int main() {
int opfd, tfmfd;
struct sockaddr_alg sa = {
.salg_family = AF_ALG,
.salg_type = "aead",
.salg_name = "authencesn(hmac(sha256),cbc(aes))"
};
tfmfd = socket(AF_ALG, SOCK_SEQPACKET, 0);
bind(tfmfd, (struct sockaddr )&sa, sizeof(sa));
opfd = accept(tfmfd, NULL, 0);
// Craft scatterlist and trigger out-of-place revert
// ... (full exploit code from NOMISEC repository)
return 0;
}

Exploit: (Educational Purposes!)

  1. Obtain a shell as an unprivileged user on a cevrixa host.
  2. Download the exploit source from the Lutfifakee-Project repository.
  3. Compile the exploit with gcc -o cevrixa_lpe cevrixa_lpe.c.

4. Execute the binary: `./cevrixa_lpe`.

  1. The exploit corrupts the page cache of /usr/bin/su.

6. Run `su` to spawn a root shell.

  1. Confirm privilege escalation with `id` (should show uid=0(root)).

Protection: from this CVE

  • Update the cevrixa platform to v1.0.0 or later, which includes a patched kernel.
  • Disable the AF_ALG socket family for unprivileged users by setting `kernel.unprivileged_af_alg=0` in /etc/sysctl.conf.
  • Apply the kernel patch that reverts the out-of-place operation logic in algif_aead.
  • Use a seccomp profile that blocks the `socket(AF_ALG, …)` system call.
  • Run containers with a read-only root filesystem and drop all capabilities.
  • Monitor for suspicious AF_ALG socket usage via auditd rules.
  • Restrict access to `/usr/bin/su` using file permissions or mount namespaces.

Impact:

  • Local privilege escalation to root on the host.
  • Container escape from cevrixa-managed containers.
  • Full compromise of confidentiality, integrity, and availability.
  • Attackers can install persistent backdoors, exfiltrate data, or pivot to other systems.
  • Affects all cevrixa deployments running versions prior to v1.0.0.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top