Copy Fail Deep Dive(CVE-2026-31431): Root Cause, Exploitation, and Detection of a Linux Page Cache Vulnerability
1. Introduction In late April 2026, security researcher Taeyang Lee publicly disclosed a Linux kernel vulnerability assigned CVE-2026-31431 and gave it an ironic name: Copy Fail. The name captures the essence of the bug. In 2017, a kernel developer fixed an AF_ALG crypto-interface bug where AAD was not copied…