Deep Dive into Copy Fail: Root Cause, Exploitation, and Detection of a Linux Page Cache Vulnerability
CVE-2026-31431 deep dive: from an optimization commit in the AF_ALG crypto subsystem to a 9-year arbitrary file page cache overwrite vulnerability. Covers root cause analysis, kernel-level dynamic verification, 7 host privilege escalation paths, cross-tenant container attacks, and a generic detection scheme based on O_DIRECT + fanotify.