Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
alg_check — Audits and hardens Linux systems against AF_ALG local privilege escalation (CVE-2026-31431) by checking kernel crypto API exposure, restricting modules, and providing restore scripts. | Kitploit
Tools/GitHubGitHub/professional-slacker/alg_check
Defensive ToolsVulnerability AnalysisConfiguration Auditing
GitHubprofessional-slacker/alg_check

alg_check

Audits and hardens Linux systems against AF_ALG local privilege escalation (CVE-2026-31431) by checking kernel crypto API exposure, restricting modules, and providing restore scripts.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
175 months agoNot yet reviewed

⚠️ Important Disclaimer: Structural Hardening Risks

This tool implements Structural Blocking to mitigate CVE-2026-31431 by physically renaming kernel modules and purging them from memory. Before use, please be aware of the following architectural risks:

  • Kernel Update Volatility: Hardening effects are temporary. A kernel update will deploy fresh, vulnerable modules under a new /lib/modules/ directory, rendering the previous obstruction void.
  • Functional Side Effects: Disabling AF_ALG (Kernel Crypto API) may break specific applications or services that rely on kernel-level hardware acceleration (e.g., specialized VPNs, disk encryption utilities, or custom security tools).[cite: 3]
  • Mitigation vs. Patching: This is a workaround, not a permanent patch. It is intended to bridge the gap until a distribution-provided patched kernel is available.

Use at your own risk. Always verify your system's critical functions after running solution.sh.[cite: 3]

SSIA - System Structural Integrity Audit

A tool kit for discovering, diagnosing, and containing LPE (Local Privilege Escalation) vectors through the Linux Kernel Crypto API (AF_ALG).

⚠️ Important Disclaimer: Structural Hardening Risks

The tool uses Structural Blocking to address CVE-2026-31431 by renaming kernel modules and purging them from memory. Key architectural risks include:

  • Kernel Update Volatility: Effects are temporary. A kernel update deploys fresh vulnerable modules under a new /lib/modules/ directory, rendering the previous obstruction void.
  • Functional Side Effects: Disabling AF_ALG may disrupt services relying on kernel-level hardware acceleration, such as specialized VPNs, disk encryption utilities, or custom security tools.
  • Mitigation vs. Patching: This is a workaround, not a permanent patch meant to serve as a bridge until a patched kernel is available.

Use at your own risk.

Overview

This repository provides two scripts that form a diagnose → contain → verify workflow against privilege escalation attacks via AF_ALG (socket(38, 5, 0)):

  • check.sh — Multi-layer security posture audit (runs unprivileged)
  • solution.sh — Force-evicts AF_ALG modules from memory + checks for physical module files (root required)
  • restore.sh — Re-loads AF_ALG modules and restores the system to pre-solution.sh state (root required)

Checks

CheckWhat it examinesSeverity
Process ContextCurrent UID/GID and effective capabilitiesLow
AF_ALG Crypto SocketKernel Crypto API accessibility via socket(AF_ALG, ...)High
kptr_restrictKernel pointer visibility to userspaceMedium
dmesg_restrictKernel ring buffer access restrictionMedium
SELinuxEnforcing / Permissive / Disabled stateMedium
/proc hidepidWhether /proc hides other processes' infoLow

Usage

Audit (unprivileged)

./check.sh

Containment (root required)

sudo ./solution.sh

Restore (root required)

sudo ./restore.sh

Restore

restore.sh reverses the effects of solution.sh by reloading the AF_ALG kernel modules (af_alg, algif_rng, algif_aead, algif_skcipher, algif_hash). If the physical module file (af_alg.ko.xz) was renamed or removed, the script will warn you and prompt for manual restoration before attempting to load modules.

⚠️ WARNING

Running solution.sh on a live system that actively uses AF_ALG (e.g., a system with IPsec, dm-crypt/LUKS, or any hardware crypto offload) will instantly break all kernel crypto operations. This includes:

  • IPsec VPN connections and WireGuard
  • Disk encryption (LUKS/dm-crypt)
  • TLS termination using kernel-backed crypto
  • Any container or application relying on algif_* socket interfaces

The script force-unloads AF_ALG kernel modules. Kernel crypto operations will fail until reboot. This script is intended only for air-gapped, non-production, or disposable systems for testing and analysis purposes. Do not run it on production or critical infrastructure.

Requirements

  • Linux (any distribution)
  • check.sh requires no dependencies beyond POSIX shell and /proc//sys
  • solution.sh requires root privileges
  • restore.sh requires root privileges
  • af_alg_block.so requires root privileges to install via /etc/ld.so.preload

WSL2 Notes

This POC has been tested on WSL2. Be aware of the following:

  • WSL2 resets all state on reboot (wsl --shutdown). This includes kernel module state changes from solution.sh, file renames, check.sh results, and any local file modifications in this repository.
  • For permanent hardening on WSL2, consider configuring .wslconfig, /etc/wsl.conf, or an auto-start script (e.g., /etc/rc.local) separately.
  • WSL2 is suitable for testing and validation purposes but not for production use or persistent security mitigation.

Mitigation

To definitively close the AF_ALG attack vector:

  1. Blacklist the kernel module (most reliable):

    echo "blacklist af_alg" | sudo tee /etc/modprobe.d/af_alg-blacklist.conf
    

    Or rename the physical file:

    sudo mv /lib/modules/$(uname -r)/kernel/crypto/af_alg.ko.xz \
            /lib/modules/$(uname -r)/kernel/crypto/af_alg.ko.xz.bak
    
  2. Disable AF_ALG via sysctl:

    sudo sysctl -w net.core.af_alg_disabled=1
    
  3. Block AF_ALG socket creation via SELinux / AppArmor policy

  4. Disable unprivileged user namespaces (container environments):

    sudo sysctl -w kernel.unprivileged_userns_clone=0
    
  5. Block AF_ALG at the socket() syscall via LD_PRELOAD (WSL2 workaround):

    # Install system-wide (requires root)
    echo /absolute/path/to/af_alg_block.so | sudo tee -a /etc/ld.so.preload
    

    A prebuilt shared library (af_alg_block.so) is included in the repository. It intercepts socket(2) and returns EAFNOSUPPORT when the domain is AF_ALG (38). All other socket calls pass through to the real implementation unchanged.

    This approach is primarily intended for WSL2 where single-user semantics and reset-on-reboot behavior make system-wide LD_PRELOAD practical. On traditional multi-user Linux systems, prefer method 1 (module blacklisting) instead — injecting via /etc/ld.so.preload affects every process on the system and may silently break AF_ALG-dependent services.

    Note: Requires glibc (not musl). /etc/ld.so.preload requires root to modify. Removal is done by deleting the corresponding line from the file.

License

MIT

Download Tool