Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vcheck — Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500) | Kitploit
Tools/GitHubGitHub/krisiasty/vcheck
Vulnerability ScannersVulnerability AnalysisConfiguration Auditing
GitHubkrisiasty/vcheck

vcheck

Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)

View Repository
21015 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

vcheck

Audit a remote Linux host over SSH for the Copy Fail and Dirty Frag kernel-module vulnerabilities and, optionally, apply mitigations:

CVENameAffected modules
CVE-2026-31431Copy Failalgif_aead
CVE-2026-43284Dirty Frag (IPsec)esp4, esp6, ipcomp4, ipcomp6, xfrm_user
CVE-2026-43500Dirty Frag (RxRPC)rxrpc, kafs

For each affected module, vcheck reports whether it is currently loaded, built into the running kernel, has past traces in kernel logs, has live AF_ALG sockets (Copy Fail only), and whether it is already blacklisted under /etc/modprobe.d/.

With -fix, vcheck reports the initial state, writes a cve-XXXX-XXXXX-disable.conf snippet for any module that is not yet blacklisted, then re-runs the checks and reports the final state. With -fix -unload, vcheck also tries to unload affected modules that were loaded before the fix, then uses the final scan to verify whether they are still loaded. With -fix -rebuild-initramfs, vcheck rebuilds the initramfs for the currently running kernel (only) after a snippet is written, so the blacklist is baked into the next boot image. Older kernel entries keep their original initramfs as a fallback.

Use -fix only after a check-only run

Always run vcheck without -fix first. Read the report and confirm the affected modules are safe to disable on this host before re-running with -fix. Disabling kernel modules that legitimate workloads depend on can affect users and break applications.

In particular:

  • Treat -fix as safe only when none of the affected modules are currently loaded — i.e. every module is reported as either mitigated or module not blacklisted (no VULNERABLE or blacklisted but currently loaded lines). A loaded module almost always means something on the host is actively using it; verify that before blacklisting.
  • The IPsec modules (esp4, esp6, ipcomp4, ipcomp6, xfrm_user) are required for any IPsec/strongSwan/WireGuard-over-IPsec/IKE deployment. The ipcomp4/ipcomp6 modules implement IPComp payload compression and may be auto-negotiated as part of an IPsec SA even when not explicitly configured. Do not blacklist any of them on a VPN gateway, IPsec endpoint, or anywhere ip xfrm policy returns rules. Note that the xfrm_algo framework module is intentionally not in this list — per vendor guidance (Red Hat, Ubuntu, AWS), blocking the ESP and IPComp protocol modules plus the xfrm_user netlink configuration interface is sufficient, and blacklisting xfrm_algo would break every other xfrm transform for no extra benefit.
  • The RxRPC modules (rxrpc, kafs) are required for any host that mounts AFS filesystems. Disabling them will break those mounts on the next boot.
  • algif_aead exposes kernel crypto via the AF_ALG socket family. It is rarely used by application code directly, but verify by listing live sockets (ss -p --af-alg) and checking userspace consumers before blacklisting.

The blacklist snippets vcheck writes only take effect at module-load time (typically next boot, or modprobe -r <module> while the system is idle). A module that is already loaded will keep running even after -fix — vcheck will report this as blacklisted but currently loaded; run 'modprobe -r' or reboot. Passing -unload with -fix asks vcheck to run modprobe -r for loaded affected modules after writing blacklist snippets. Use it only when you have confirmed the modules are safe to remove from the running kernel.

Passing -rebuild-initramfs with -fix regenerates the initramfs for the currently running kernel only (update-initramfs -u -k $(uname -r) on Debian/Ubuntu, dracut -f --kver $(uname -r) on RHEL/Fedora). Other installed kernels keep their existing initramfs untouched, so if something goes wrong after reboot you can pick an older kernel entry from the boot menu and recover. Future kernel installs rebuild their own initramfs from the current /etc/modprobe.d/ state, so the blacklist propagates automatically without re-running vcheck. If neither update-initramfs nor dracut is present (e.g. Arch, Alpine, immutable images), vcheck warns and continues — rebuild manually with the distro's tool before rebooting.

The rebuild can take several minutes (especially dracut on hosts with many drivers), which would exceed the diagnostic -command-timeout. It runs under its own -initramfs-timeout (default 10m) so the rebuild gets the room it needs while the fast checks keep their tight budget. Bump -initramfs-timeout for slow hardware, or pass 0 to disable the timeout entirely. During long-running remote commands, vcheck sends SSH keepalive requests every 30s by default to keep NAT/firewall idle timers from dropping the connection. Tune this with -ssh-keepalive, or pass 0 to disable it.

Installation

Homebrew (macOS):

brew install --cask krisiasty/tap/vcheck

Pre-built binaries for Linux, macOS, and Windows are published on the releases page.

From source (requires Go 1.26+):

go install github.com/krisiasty/vcheck@latest

Usage

vcheck -host HOST [flags]
Download Tool