
Ansible playbook for detecting and remediating CVE-2026-31431 (Copy Fail) - Linux kernel local privilege escalation vulnerability
Copy Fail Detection and Remediation
An Ansible role and playbook suite for detecting and remediating CVE-2026-31431 (Copy Fail), a critical local privilege escalation vulnerability in the Linux kernel's algif_aead module.
🔗 GitHub: https://github.com/parmstro/cfDr
The name cfDr is a play on "Copy Fail Doctor" - your trusted remedy for CVE-2026-31431.
CVE-2026-31431 (CVSS 7.8) is a logic flaw in the Linux kernel's AEAD socket interface (AF_ALG) discovered in 2026. The vulnerability allows any unprivileged local user to escalate privileges to root in seconds.
algif_aead kernel module (AF_ALG crypto interface)Kernel Versions: Linux kernel >= 4.10 (released 2017)
Distributions Affected:
Note: Any Linux distribution with kernel 4.10 or newer is potentially vulnerable.
This vulnerability is particularly dangerous because:
Once an attacker has any form of local access (SSH, web shell, container escape, etc.), they can:
While waiting for vendor-supplied kernel patches, several mitigation strategies are available. cfDr implements all of them, with intelligent recommendations based on your system configuration.
Not all remediations are equal. Here's what you need to know:
| Method | Can Root Bypass? | Coverage | Enterprise Linux Support |
|---|---|---|---|
| Module Blacklist | ✅ Yes (via insmod) | Prevents modprobe loading | All versions |
| SELinux Policy | ❌ NO (LSM layer) | Configured domains only | All versions (default) |
| systemd seccomp | ❌ NO (syscall filter) | Configured services only | All versions |
| eBPF LSM | ❌ NO (LSM layer) | System-wide (if configured) | RHEL 9+, Fedora 34+ |
cfDr's default recommendation: Flag 3 (Module Blacklist + SELinux)
This provides two independent protection layers:
┌─────────────────────────────────────────────────┐
│ Layer 1: Module Blacklist │
│ • Prevents modprobe algif_aead │
│ • Persists across reboots │
│ • CAN be bypassed by malicious root (insmod) │
├─────────────────────────────────────────────────┤
│ Layer 2: SELinux Policy │
│ • Blocks AF_ALG socket() at syscall level │
│ • Works even if module is loaded │
│ • CANNOT be bypassed from userspace │
│ • Covers user_t, unconfined_t (majority cases) │
└─────────────────────────────────────────────────┘
Result: If either layer fails, the other still protects
A determined attacker with root access can bypass module blacklisting:
# Module blacklist DOES NOT prevent:
insmod /lib/modules/$(uname -r)/kernel/crypto/algif_aead.ko.xz
However, this is acceptable because:
For complete, non-bypassable protection, you need:
Module Blacklist + at least one of:
cfDr uses bitwise flags to enable multiple mitigations:
| Flag Value | Mitigations Enabled | Use Case |
|---|---|---|
| 1 | Module Blacklist only | Minimal protection, systems without SELinux |
| 2 | SELinux only | SELinux-only environments |
| 3 | Module Blacklist + SELinux | RECOMMENDED default |
| 5 | Module Blacklist + seccomp | Non-SELinux with service hardening |
| 7 | Module Blacklist + SELinux + seccomp | Enhanced protection |
| 15 | All mitigations | Maximum protection (RHEL 9+ only) |
Calculate flags: 1 (blacklist) + 2 (SELinux) + 4 (seccomp) + 8 (eBPF) = sum
SELinux Protection:
user_t, unconfined_t, httpd_t, postgresql_t, mysqld_tuser_t and unconfined_t cover the vast majority of attack scenariossystemd seccomp Protection:
httpd, nginx, postgresql, mariadb, redis, memcachedeBPF LSM Protection:
cfDr performs comprehensive assessment across multiple dimensions:
uname -r
modinfo algif_aead
algif_aead module exists in the kernellsmod | grep algif_aead
lsof -U | grep AF_ALG
Module Blacklist:
grep -E "blacklist algif_aead|install algif_aead" /etc/modprobe.d/*.conf
SELinux Policy:
semodule -l | grep cve_2026_31431_af_alg_deny
systemd seccomp:
systemctl show <service> | grep RestrictAddressFamilies
cfDr categorizes each host into one of these states: