Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/juliosuas/copyfail-guard
Defensive ToolsContainer SecurityVulnerability AnalysisConfiguration AuditingCloud SecurityDevSecOpsIncident Response
GitHubjuliosuas/copyfail-guard

copyfail-guard

Fast, auditable Linux mitigation for CVE-2026-31431 Copy Fail: algif_aead block, verification, and AF_ALG seccomp hardening.

View Repository
21322 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CopyFail Guard

CI License: MIT Platform Shell No exploit code

   ______                 ______      _ __   ______                     __
  / ____/___  ____  __  _/ ____/___ _(_) /  / ____/_  ______ __________/ /
 / /   / __ \/ __ \/ / / / /_  / __ `/ / /  / / __/ / / / __ `/ ___/ __  /
/ /___/ /_/ / /_/ / /_/ / __/ / /_/ / / /  / /_/ / /_/ / /_/ / /  / /_/ /
\____/\____/ .___/\__, /_/    \__,_/_/_/   \____/\__,_/\__,_/_/   \__,_/
          /_/    /____/

Fast, auditable Linux exposure assessment and mitigation for CVE-2026-31431 “Copy Fail” while kernels get patched.

CopyFail Guard is a defensive operations tool for Linux sysadmins, DevSecOps engineers, platform teams, and incident responders. It helps reduce exposure to the Linux algif_aead / AF_ALG issue by:

  • safely assessing exposure without exploit code
  • checking whether algif_aead is available, loaded, built-in, or already blocked
  • installing a persistent modprobe.d block and unloading the module when safe
  • adding an AF_ALG-deny rule to Docker, Podman, and Kubernetes seccomp profiles
  • validating AF_ALG reachability without shipping exploit code

Final fix: install your vendor’s patched kernel and reboot.
This tool covers the operational gap between disclosure and full fleet patching.

Why operators can trust it

  • No exploit code: checks exposure and AF_ALG reachability without page-cache writes, splice, setuid changes, privilege escalation, or destructive probes.
  • Auditable host change: host mitigation writes one managed file, /etc/modprobe.d/99-copyfail-guard.conf, and rollback removes only that file.
  • Baseline-preserving seccomp: seccomp-patch adds an AF_ALG denial to an existing Docker/Podman/Kubernetes seccomp profile instead of replacing your runtime hardening.
  • Automation ready: assess --json and documented exit codes support fleet scans, SIEM capture, and change-management evidence.
  • CI covered: shell syntax, seccomp profile generation, JSON output, and smoke tests run across common Linux distro containers.

30-second path

If you are on a Linux host and need a quick answer:

git clone --depth 1 https://github.com/juliosuas/copyfail-guard.git
cd copyfail-guard
sudo ./bin/copyfail-guard.sh doctor
sudo ./bin/copyfail-guard.sh assess

If the verdict is exposed and algif_aead is modular:

sudo ./bin/copyfail-guard.sh mitigate --yes
sudo ./bin/copyfail-guard.sh verify

For repeatable installs, pin a release tag:

git clone --branch v0.3.0 --depth 1 https://github.com/juliosuas/copyfail-guard.git

Replace v0.3.0 with the latest tagged release when newer releases are available.

Am I affected?

Run the safe exposure check first:

sudo ./bin/copyfail-guard.sh assess

How to read the result:

Verdict familyWhat it meansWhat to do
EXPOSED_*algif_aead / AF_ALG appears reachable or loadableMitigate now, then patch and reboot
PARTIALLY_MITIGATED_*A block exists but the loaded module or reboot state still mattersReboot or unload safely, then verify
INTERIM_MITIGATED_*Local mitigation is activeKeep it, but still patch and reboot
LOW_OBVIOUS_EXPOSURE_*Local checks did not find obvious algif_aead exposureConfirm vendor patch status anyway

If you run untrusted containers, CI jobs, sandboxes, or multi-user workloads, also test whether AF_ALG socket creation is blocked inside that runtime:

python3 tools/afalg-socket-test.py

PERMITTED does not prove successful exploitation, but it proves the relevant userspace crypto API is reachable. For defensive operations, that is enough reason to apply the mitigation while you confirm the patched kernel rollout.

Does this prove vulnerability?

No destructive proof of concept is included. That is a feature, not a gap.

A real Copy Fail exploit proof would need to validate kernel memory/page-cache impact or privilege escalation. Shipping that in a public mitigation repo would make the project less safe and less deployable in production.

CopyFail Guard proves the things operators can safely act on:

  • whether the risky component is available, loaded, built-in, or blocked
  • whether AF_ALG socket creation is permitted in a target runtime
  • whether the host has an interim mitigation in place
  • whether the remaining required action is unload, reboot, seccomp, or vendor patching

For final vulnerability status, combine this tool with vendor advisory/package inventory and reboot evidence.

Resolution model

CopyFail Guard is mitigation, not cure. It reduces exposure and verifies interim controls. The durable fix remains vendor patched kernel plus reboot.

The tool is intentionally clone-and-run for incident response: no compiler, kernel headers, exploit code, or third-party package manager is required for the core host workflow. python3 is needed for --json output, seccomp-patch, and the non-exploit AF_ALG socket test.

Quick start

Clone-and-run:

git clone https://github.com/juliosuas/copyfail-guard.git
cd copyfail-guard
chmod +x bin/copyfail-guard.sh

sudo ./bin/copyfail-guard.sh doctor
sudo ./bin/copyfail-guard.sh assess
sudo ./bin/copyfail-guard.sh mitigate --yes
sudo ./bin/copyfail-guard.sh verify

Optional system install:

git clone https://github.com/juliosuas/copyfail-guard.git
cd copyfail-guard
sudo ./scripts/install.sh
sudo copyfail-guard status

The installer supports pinning the source and destination for controlled rollouts:

sudo env COPYFAIL_GUARD_REF=v0.3.0 ./scripts/install.sh

Use the latest tagged release for COPYFAIL_GUARD_REF when newer releases are available.

Container / CI hardening:

./bin/copyfail-guard.sh seccomp-patch docker-default.json copyfail-seccomp.json
docker run --security-opt seccomp=./copyfail-seccomp.json IMAGE

Validate that AF_ALG is blocked inside a protected container:

docker run --rm \
  --security-opt seccomp=./copyfail-seccomp.json \
  -v "$PWD/tools:/tools:ro" \
  python:3.12-alpine \
  python /tools/afalg-socket-test.py

Expected protected result:

BLOCKED: socket(AF_ALG) denied by policy (...)

See Sample outputs for expected verdicts, JSON shape, and container validation results.

Why this matters

Copy Fail is a Linux kernel local privilege escalation in the algif_aead component of the AF_ALG userspace crypto API. Public advisories describe a page-cache write primitive reachable by unprivileged local users and especially dangerous on shared-kernel systems: Kubernetes nodes, CI/CD runners, multi-tenant hosts, agent sandboxes, and developer boxes.

The correct fix is a vendor kernel update containing the upstream revert/fix and a reboot into the patched kernel. CopyFail Guard is a defensive operations helper for the window before that reboot is complete across the fleet.

What the tool does

Download Tool