
Automated scanner and patch helper for CVE-2026-31431, detecting vulnerable Linux hosts via SSH, verifying kernel versions, and applying kernel upgrades or temporary mitigations across multiple distributions.
Copy Fail is an automated security scanner and patch helper for detecting and remediating the CVE-2026-31431 vulnerability (Linux Kernel algif_aead Local Privilege Escalation) across your Linux infrastructure.
CVE-2026-31431 is a Local Privilege Escalation (LPE) vulnerability in the Linux kernel module algif_aead (Asynchronous Cipher Interface for AEAD). This vulnerability allows local users to escalate privileges to root level.
This tool helps you:
Note: This tool is intended solely for internal audit and patching purposes by sysadmins. Use it only on systems you own or are authorized to access.

algif_aead module (loaded/not loaded)Automatically upgrade the kernel on vulnerable hosts via the package manager:
Option: Automatic reboot after patching is complete
algif_aead module via modprobe.d configurationDatabase of patched kernel versions for:
paramiko>=3.0.0 # SSH library
rich>=13.0.0 # Beautiful terminal UI
git clone https://github.com/gagaltotal/cve-2026-31431-copy-fail.git
cd cve-2026-31431-copy-fail
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
or install manually:
pip install paramiko>=3.0.0 rich>=13.0.0
python3 copyfail_scanner.py --help
# Scan subnet with SSH key
python3 copyfail_scanner.py --subnet <CIDR> --user <USERNAME> --key <PATH_TO_KEY>
# Scan multiple specific hosts
python3 copyfail_scanner.py --hosts <IP1>,<IP2>,<IP3> --user <USERNAME> [--password <PASSWORD>]
# Scan + automatic patch
python3 copyfail_scanner.py --subnet <CIDR> --user <USERNAME> --key <PATH> --patch
# Scan + temporary mitigation
python3 copyfail_scanner.py --subnet <CIDR> --user <USERNAME> --key <PATH> --mitigate
| Option | Description | Example |
|---|---|---|
--subnet | Target subnet CIDR (mutually exclusive with --hosts) | --subnet 192.168.1.0/24 |
--hosts | Comma-separated IP list (mutually exclusive with --subnet) | --hosts 192.168.1.10,192.168.1.20 |
--user | SSH username (required) | --user root |
--password | SSH password (optional, use if no key) | --password secret123 |
--key | SSH private key path | --key ~/.ssh/id_rsa |
--port | SSH port (default: 22) | --port 2222 |
--threads | Number of parallel threads (default: 30) | --threads 50 |
--patch | Automatically upgrade kernel on vulnerable hosts | --patch |
--reboot | Automatic reboot after patching (use with --patch) | --patch --reboot |
--mitigate | Apply temporary mitigation (disable algif_aead) | --mitigate |
--output | Export scan results to a JSON file | --output results.json |
--yes | Skip confirmation prompt before patch/mitigate | --yes |
python3 copyfail_scanner.py \
--subnet 192.168.1.0/24 \
--user ubuntu \
--key ~/.ssh/id_rsa
Output: Displays the scan results table and summary
python3 copyfail_scanner.py \
--hosts 10.0.1.5,10.0.1.6,10.0.1.7 \
--user admin \
--password my_password123
python3 copyfail_scanner.py \
--subnet 172.16.0.0/16 \
--user root \
--key ~/.ssh/id_rsa \
--mitigate
Action: Scan all hosts, then disable the algif_aead module on vulnerable hosts (prompts for confirmation)
python3 copyfail_scanner.py \
--subnet 192.168.0.0/24 \
--user ubuntu \
--key ~/.ssh/id_rsa \
--patch
Action: Upgrade the kernel, but do not reboot automatically (requires manual reboot)
python3 copyfail_scanner.py \
--subnet 10.10.0.0/24 \
--user root \
--key ~/.ssh/id_rsa \
--patch \
--reboot \
--yes
Action: Scan, patch the kernel, reboot automatically, skip confirmation
python3 copyfail_scanner.py \
--subnet 192.168.1.0/24 \
--user sysadmin \
--key ~/.ssh/id_rsa \
--output scan_results_$(date +%Y%m%d_%H%M%S).json
Output: Table in the terminal + JSON results in a file