
Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)
Audit a remote Linux host over SSH for the Copy Fail and Dirty Frag kernel-module vulnerabilities and, optionally, apply mitigations:
| CVE | Name | Affected modules |
|---|---|---|
| CVE-2026-31431 | Copy Fail | algif_aead |
| CVE-2026-43284 | Dirty Frag (IPsec) | esp4, esp6, ipcomp4, ipcomp6, xfrm_user |
| CVE-2026-43500 | Dirty Frag (RxRPC) | rxrpc, kafs |
For each affected module, vcheck reports whether it is currently loaded, built into the running kernel, has past traces in kernel logs, has live AF_ALG sockets (Copy Fail only), and whether it is
already blacklisted under /etc/modprobe.d/.
With -fix, vcheck reports the initial state, writes a cve-XXXX-XXXXX-disable.conf snippet for any module that is not yet blacklisted, then re-runs the checks and reports the final state. With
-fix -unload, vcheck also tries to unload affected modules that were loaded before the fix, then uses the final scan to verify whether they are still loaded. With -fix -rebuild-initramfs, vcheck
rebuilds the initramfs for the currently running kernel (only) after a snippet is written, so the blacklist is baked into the next boot image. Older kernel entries keep their original initramfs as a
fallback.
-fix only after a check-only runAlways run vcheck without -fix first. Read the report and confirm the affected modules are safe to disable on this host before re-running with -fix. Disabling kernel modules that legitimate
workloads depend on can affect users and break applications.
In particular:
-fix as safe only when none of the affected modules are currently loaded — i.e. every module is reported as either mitigated or module not blacklisted (no VULNERABLE or
blacklisted but currently loaded lines). A loaded module almost always means something on the host is actively using it; verify that before blacklisting.esp4, esp6, ipcomp4, ipcomp6, xfrm_user) are required for any IPsec/strongSwan/WireGuard-over-IPsec/IKE deployment. The ipcomp4/ipcomp6 modules implement IPComp
payload compression and may be auto-negotiated as part of an IPsec SA even when not explicitly configured. Do not blacklist any of them on a VPN gateway, IPsec endpoint, or anywhere ip xfrm policy
returns rules. Note that the xfrm_algo framework module is intentionally not in this list — per vendor guidance (Red Hat, Ubuntu, AWS), blocking the ESP and IPComp protocol modules plus the
xfrm_user netlink configuration interface is sufficient, and blacklisting xfrm_algo would break every other xfrm transform for no extra benefit.rxrpc, kafs) are required for any host that mounts AFS filesystems. Disabling them will break those mounts on the next boot.algif_aead exposes kernel crypto via the AF_ALG socket family. It is rarely used by application code directly, but verify by listing live sockets (ss -p --af-alg) and checking userspace
consumers before blacklisting.The blacklist snippets vcheck writes only take effect at module-load time (typically next boot, or modprobe -r <module> while the system is idle). A module that is already loaded will keep running
even after -fix — vcheck will report this as blacklisted but currently loaded; run 'modprobe -r' or reboot. Passing -unload with -fix asks vcheck to run modprobe -r for loaded affected
modules after writing blacklist snippets. Use it only when you have confirmed the modules are safe to remove from the running kernel.
Passing -rebuild-initramfs with -fix regenerates the initramfs for the currently running kernel only (update-initramfs -u -k $(uname -r) on Debian/Ubuntu, dracut -f --kver $(uname -r) on
RHEL/Fedora). Other installed kernels keep their existing initramfs untouched, so if something goes wrong after reboot you can pick an older kernel entry from the boot menu and recover. Future kernel
installs rebuild their own initramfs from the current /etc/modprobe.d/ state, so the blacklist propagates automatically without re-running vcheck. If neither update-initramfs nor dracut is
present (e.g. Arch, Alpine, immutable images), vcheck warns and continues — rebuild manually with the distro's tool before rebooting.
The rebuild can take several minutes (especially dracut on hosts with many drivers), which would exceed the diagnostic -command-timeout. It runs under its own -initramfs-timeout (default 10m)
so the rebuild gets the room it needs while the fast checks keep their tight budget. Bump -initramfs-timeout for slow hardware, or pass 0 to disable the timeout entirely. During long-running
remote commands, vcheck sends SSH keepalive requests every 30s by default to keep NAT/firewall idle timers from dropping the connection. Tune this with -ssh-keepalive, or pass 0 to disable it.
Homebrew (macOS):
brew install --cask krisiasty/tap/vcheck
Pre-built binaries for Linux, macOS, and Windows are published on the releases page.
From source (requires Go 1.26+):
go install github.com/krisiasty/vcheck@latest
vcheck -host HOST [flags]