Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve_2026_frag_family_fix — CVE-2026-46300 / CVE-2026-43500 / CVE-2026-31431 / CVE-2026-43284 golang hotfix | Kitploit
Tools/GitHubGitHub/first-john/cve_2026_frag_family_fix
Cloud Infrastructure SecurityVulnerability ScannersVulnerability AnalysisScripting & AutomationConfiguration AuditingCloud SecurityDevSecOps
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
first-john/cve_2026_frag_family_fix

cve_2026_frag_family_fix

CVE-2026-46300 / CVE-2026-43500 / CVE-2026-31431 / CVE-2026-43284 golang hotfix

View RepositoryWebsite
1152 months agoNot yet reviewed
Share

ПО для устранения уязвимостей frag family / Mitigation tool for frag family vulnerability

  • Copy Fail (2026)
  • Dirty Frag (2026)
  • Fragnesia (2026)
  • DirtyClone (2026)
  • PEdit-CoW (2026)

Запустить исправление на любом Linux / Run any Linux hotfix

b="/tmp/cve_2026_frag_family_fix"; wget -qO $b $(wget -qO- https://bit.ly/4vetMTB | grep browser_download_url | grep -v .exe | cut -d '"' -f 4) && chmod +x $b && $b

или

b="/tmp/cve_2026_frag_family_fix"; curl -fsSL "$(curl -fsSL https://bit.ly/4vetMTB | grep browser_download_url | grep -v .exe | cut -d '"' -f 4)" -o $b && chmod +x $b && $b

CVE-2026-46300 / CVE-2026-43500 / CVE-2026-43284 / CVE-2026-46300 / CVE-2026-46331

Описание

  • проверяет включенные модули из CVE-2026-46300 / CVE-2026-43500 / CVE-2026-43284 / CVE-2026-46300 / CVE-2026-46331
  • предлагает обновление ядра если доступно
  • отключает esp4, esp6, rxrpc, act_pedit если нет
  • блокирует загрузку через modprobe
  • добавляет module_blacklist в grub
  • автоматически очищает хотфикс после обновления ядра
  • для RHEL-совместимых систем (AlmaLinux, Rocky, Oracle, Fedora) отключает Boot Loader Specification (GRUB_ENABLE_BLSCFG=false), устанавливает GRUB_DEFAULT=0 и создаёт хук установки ядра (/etc/kernel/install.d/99-grub-update.install), который обновляет конфигурацию grub после обновления ядра, чтобы при следующей загрузке запускалось самое свежее ядро.
  • для минорных релизов предлагает и выполняет обновление до последней минорной версии для которой есть обновление ядра

Description

  • checks for CVE-2026-46300 / CVE-2026-43500 / CVE-2026-43284 / CVE-2026-46300 / CVE-2026-46331 vulnerability enabled modules
  • offers kernel update if available
  • disables esp4, esp6, rxrpc, act_pedit if not
  • blocks module loading via modprobe
  • adds module_blacklist to grub
  • automatically cleans up hotfix after kernel update
  • for RHEL-based systems (AlmaLinux, Rocky, Oracle, Fedora), disables Boot Loader Specification (GRUB_ENABLE_BLSCFG=false) and sets GRUB_DEFAULT=0, then creates a kernel install hook (/etc/kernel/install.d/99-grub-update.install) that regenerates grub config after kernel updates to ensure the most recent kernel loads on next boot
  • for minor releases, it offers and performs an update to the latest minor version that has a kernel update available.

CVE-2026-31431 / Copy Fail mitigation (algif_aead)

Описание

Утилита проверяет уязвимость CVE-2026-31431 (pre condition) и при наличии root-привилегий применяет mitigation:

  • определяет защищённые комбинации ОС (включая WSL) и версий ядра
  • предлагает обновление ядра с исправлением если оно доступно
  • отключает algif_aead если нет
  • блокирует загрузку через modprobe
  • добавляет initcall_blacklist=algif_aead_init
  • ограничивает AF_ALG через systemd

Description

This tool checks for CVE-2026-31431 (pre condition) and applies mitigation (requires root):

  • identifies protected combinations of OS (including WSL) and kernel versions
  • offers a kernel update with a fix if available
  • disables algif_aead if not
  • blocks module loading via modprobe
  • adds initcall_blacklist=algif_aead_init
  • restricts AF_ALG via systemd

Linux сборка / build

docker run --rm -v "$PWD":/app -w /app golang:alpine sh -c "apk add --no-cache upx && go build -ldflags='-s -w' -o cve_2026_frag_family_fix cve_2026_frag_family_fix.go && upx --best --ultra-brute cve_2026_frag_family_fix"

Обновление ядра (не хотфикс) доступно для / Kernel update (not hotfix) is exist for

OSCopy Fail
(CVE-2026-31431)
Dirty Frag
(CVE-2026-43500/43284)
Fragnesia
(CVE-2026-46300)
PEdit-CoW
(CVE-2026-46331)
Debian 10 (buster)❌❌❌❌
Debian 11 (bullseye)✅✅✅✅
Debian 12 (bookworm)✅✅✅✅
Debian 13 (trixie)✅✅✅✅
Ubuntu 18.04 (bionic)❌❌❌❌
Ubuntu 20.04 (focal)❌❌❌❌
Ubuntu 22.04 (jammy)✅❌❌❌
Ubuntu 24.04 (noble)✅✅✅❌
Ubuntu 25.04 (plucky)❌❌❌❌
Ubuntu 26.04 (resolute)✅✅✅✅
CentOS Stream 8❌❌❌❌
CentOS Stream 9✅✅✅✅
CentOS Stream 10✅✅✅✅
AlmaLinux 8✅✅✅✅
AlmaLinux 9✅✅✅✅
AlmaLinux 10✅✅✅✅
Rocky Linux 8✅✅✅✅
Rocky Linux 9✅✅✅✅
Rocky Linux 10✅✅✅✅
Fedora 40❌❌❌❌
Fedora 41❌❌❌❌
Fedora 42✅✅✅✅
Fedora 43✅✅✅✅
Fedora 44✅✅✅✅
Oracle Linux 8✅✅✅✅
Oracle Linux 9✅✅✅✅
Oracle Linux 10✅✅✅✅

Команды обновления ядра / Kernel update commands

  • Debian apt update && apt install linux-image-amd64 linux-headers-amd64 -y
  • Ubuntu apt update && apt install linux-image-generic linux-headers-generic -y
  • CentOS dnf clean metadata && dnf upgrade 'kernel*' -y
  • AlmaLinux dnf clean metadata && dnf upgrade 'kernel*' -y
  • RockyLinux dnf clean metadata && dnf upgrade 'kernel*' -y
  • Fedora dnf clean metadata && dnf upgrade 'kernel*' -y
  • OracleLinux dnf clean metadata && dnf upgrade 'kernel*' -y
Download Tool