Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-31431-copy-fail — Automated scanner and patch helper for CVE-2026-31431, detecting vulnerable Linux hosts via SSH, verifying kernel versions, and applying kernel upgrades or temporary mitigations across multiple distributions. | Kitploit
Tools/GitHubGitHub/gagaltotal/cve-2026-31431-copy-fail
Vulnerability ScannersConfiguration AuditingNetwork Security
GitHubgagaltotal/cve-2026-31431-copy-fail

cve-2026-31431-copy-fail

Automated scanner and patch helper for CVE-2026-31431, detecting vulnerable Linux hosts via SSH, verifying kernel versions, and applying kernel upgrades or temporary mitigations across multiple distributions.

View Repository
2215 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31431 "Copy Fail" Scanner & Patch Helper

CVE-2026-31431 CVSS Python License

Copy Fail is an automated security scanner and patch helper for detecting and remediating the CVE-2026-31431 vulnerability (Linux Kernel algif_aead Local Privilege Escalation) across your Linux infrastructure.


Table of Contents

  • Description
  • Key Features
  • Requirements
  • Installation
  • Usage
  • Command Options
  • Usage Examples
  • Output & Results
  • Supported Distributions
  • Manual Patch Guide
  • Temporary Mitigation
  • Troubleshooting
  • Security References

Description

CVE-2026-31431 is a Local Privilege Escalation (LPE) vulnerability in the Linux kernel module algif_aead (Asynchronous Cipher Interface for AEAD). This vulnerability allows local users to escalate privileges to root level.

This tool helps you:

  • Automatically scan Linux subnets to detect vulnerable hosts
  • Verify patch status for each host based on kernel version
  • Automatically patch by upgrading the kernel via the package manager
  • Apply temporary mitigation by disabling the algif_aead module
  • Generate structured reports in table and JSON formats

Note: This tool is intended solely for internal audit and patching purposes by sysadmins. Use it only on systems you own or are authorized to access.


Example Screenshot

Screen Capture

Key Features

1. Scalable Scanning

  • Scan a single host, multiple hosts, or an entire subnet
  • Parallel SSH connections with a thread pool (default: 30 threads)
  • Real-time progress bar with Rich UI
  • Automatic retries with exponential backoff for unstable connections

2. Vulnerability Detection

  • Check SSH reachability and authentication
  • Read the kernel version of each host
  • Verify whether the kernel is already patched (based on per-distro database)
  • Detect the status of the algif_aead module (loaded/not loaded)
  • Check whether modprobe.d mitigation has been applied

3. Automatic Patching

Automatically upgrade the kernel on vulnerable hosts via the package manager:

  • apt (Debian/Ubuntu)
  • dnf (Fedora/RHEL 8+)
  • yum (RHEL 7, CentOS 7)
  • zypper (SUSE/openSUSE)
  • pacman (Arch Linux)

Option: Automatic reboot after patching is complete

4. Temporary Mitigation

  • Disable the algif_aead module via modprobe.d configuration
  • Suitable as a temporary fix while waiting for a maintenance window to reboot
  • Note: Not effective on RHEL-family systems if the module is built into the kernel

5. Flexible SSH Authentication

  • SSH key-based authentication (recommended)
  • Password-based authentication
  • Custom SSH port support
  • Connection pooling for resource optimization

6. Comprehensive Security Database

Database of patched kernel versions for:

  • Ubuntu (6.8.0-60, 5.15.0-130, 5.4.0-216)
  • RHEL / CentOS / AlmaLinux / Rocky (5.14.0-570)
  • Fedora (6.14.4, 6.13.12, 6.12.25)
  • Debian (6.1.137, 5.10.235)
  • Arch Linux (6.14.4)
  • Amazon Linux (6.1.134, 5.10.235, 4.14.353)
  • SUSE / openSUSE (6.4.0-18, 5.14.21-150600.24)

7. Comprehensive Reporting

  • Color-coded scan results table (Rich format)
  • Summary statistics (total hosts, vulnerable, patched, etc.)
  • Export results to JSON for integration with other systems
  • Error tracking and retry count per host

Requirements

System Requirements

  • Python: 3.7 or newer
  • OS: Linux/Mac/Windows (with WSL)
  • Network: SSH access to target hosts
  • SSH Key or Password: For authentication

Python Dependencies

paramiko>=3.0.0    # SSH library
rich>=13.0.0       # Beautiful terminal UI

Installation

1. Clone Repository

git clone https://github.com/gagaltotal/cve-2026-31431-copy-fail.git
cd cve-2026-31431-copy-fail

2. Create Virtual VENV

python3 -m venv .venv
source .venv/bin/activate

3. Install Dependencies

pip install -r requirements.txt

or install manually:

pip install paramiko>=3.0.0 rich>=13.0.0

4. Verify Installation

python3 copyfail_scanner.py --help

Usage

Basic Syntax

# Scan subnet with SSH key
python3 copyfail_scanner.py --subnet <CIDR> --user <USERNAME> --key <PATH_TO_KEY>

# Scan multiple specific hosts
python3 copyfail_scanner.py --hosts <IP1>,<IP2>,<IP3> --user <USERNAME> [--password <PASSWORD>]

# Scan + automatic patch
python3 copyfail_scanner.py --subnet <CIDR> --user <USERNAME> --key <PATH> --patch

# Scan + temporary mitigation
python3 copyfail_scanner.py --subnet <CIDR> --user <USERNAME> --key <PATH> --mitigate

Command Options

OptionDescriptionExample
--subnetTarget subnet CIDR (mutually exclusive with --hosts)--subnet 192.168.1.0/24
--hostsComma-separated IP list (mutually exclusive with --subnet)--hosts 192.168.1.10,192.168.1.20
--userSSH username (required)--user root
--passwordSSH password (optional, use if no key)--password secret123
--keySSH private key path--key ~/.ssh/id_rsa
--portSSH port (default: 22)--port 2222
--threadsNumber of parallel threads (default: 30)--threads 50
--patchAutomatically upgrade kernel on vulnerable hosts--patch
--rebootAutomatic reboot after patching (use with --patch)--patch --reboot
--mitigateApply temporary mitigation (disable algif_aead)--mitigate
--outputExport scan results to a JSON file--output results.json
--yesSkip confirmation prompt before patch/mitigate--yes

Usage Examples

Example 1: Basic Subnet Scan (Read-Only)

python3 copyfail_scanner.py \
  --subnet 192.168.1.0/24 \
  --user ubuntu \
  --key ~/.ssh/id_rsa

Output: Displays the scan results table and summary


Example 2: Scan Specific Hosts with Password

python3 copyfail_scanner.py \
  --hosts 10.0.1.5,10.0.1.6,10.0.1.7 \
  --user admin \
  --password my_password123

Example 3: Scan + Temporary Mitigation

python3 copyfail_scanner.py \
  --subnet 172.16.0.0/16 \
  --user root \
  --key ~/.ssh/id_rsa \
  --mitigate

Action: Scan all hosts, then disable the algif_aead module on vulnerable hosts (prompts for confirmation)


Example 4: Scan + Automatic Patch (Without Reboot)

python3 copyfail_scanner.py \
  --subnet 192.168.0.0/24 \
  --user ubuntu \
  --key ~/.ssh/id_rsa \
  --patch

Action: Upgrade the kernel, but do not reboot automatically (requires manual reboot)


Example 5: Scan + Patch + Automatic Reboot

python3 copyfail_scanner.py \
  --subnet 10.10.0.0/24 \
  --user root \
  --key ~/.ssh/id_rsa \
  --patch \
  --reboot \
  --yes

Action: Scan, patch the kernel, reboot automatically, skip confirmation


Example 6: Scan + Export JSON Results

python3 copyfail_scanner.py \
  --subnet 192.168.1.0/24 \
  --user sysadmin \
  --key ~/.ssh/id_rsa \
  --output scan_results_$(date +%Y%m%d_%H%M%S).json

Output: Table in the terminal + JSON results in a file


Download Tool