Copy Fail Explained [CVE-2026-31431]

Опубликовано: 13 Май 2026
на канале: 0xdf
13,363
456

Copy Fail is the latest Linux privesc CVE, and it's a relatively simply exploit that overwrites files in the in-memory cache. The exploit will abuse this by overwriting the cahce for a SetUID binary and then running it. In this video I'll walk though the author's POC, show my own deobfuscated POC, and show how the vulnerability works. To close, I'll run it on the HTB Snapped machine and show how to cleanup the exploit.

Copy-Fail: https://copy.fail/#exploit
Original POC: https://github.com/theori-io/copy-fai...
Deobfuscated POC: https://github.com/0xdf223/copy-fail-...
HTB Snapped post: https://0xdf.gitlab.io/2026/04/01/htb...

☕ Buy Me A Coffee: https://www.buymeacoffee.com/0xdf

[00:00] Introduction
[01:13] Author's writeup
[02:00] Author's POC
[04:25] Deobfuscated POC
[04:26] Three interesting cases: shadow, root.txt, .bash_history
[05:17] Vulnerability / exploit overview
[06:56] Walking through POC
[08:52] Analysis of the compressed hex payload
[13:04] Running on HTB Snapped
[13:55] Cleanup
[14:55] Conclusion

#copy-fail #privescc #cybersecurity