
Tutorial Completo: Como Proteger seu contra a Vulnerabilidade CopyFail (CVE-2026-31431)
This repository contains detailed tutorials and scripts to mitigate the CopyFail vulnerability (CVE-2026-31431). This flaw affects the Linux Kernel cryptography subsystem (AF_ALG) and allows local privilege escalation (LPE) from a regular user to root.
📁 Repository Structure The repository is organized by distribution to make it easier to apply in specific infrastructure environments:
/Ubuntu: Guide for Ubuntu 20.04, 22.04, and 24.04.
/RockyLinux: Guide for Rocky Linux 8 and 9 (RHEL standard).
/Debian: Guide for Debian 12 and 13 (Trixie).
/openSUSE: Guide for openSUSE Leap 15.x.
/Scripts: Automated verification and monitoring script.
🚀 How to Use This Material
Bash python3 -c "import socket; s=socket.socket(socket.AF_ALG, socket.SOCK_SEQPACKET, 0); s.close(); print('VETOR ATIVO')" 2>/dev/null || echo "✅ Protegido/Vetor Bloqueado" 2. Choose the Mitigation Method The PDF and Markdown tutorials inside the folders cover two scenarios:
Method A (Module Blacklist): For kernels where algif_aead is loaded as a module (=m). Does not require a reboot.
Method B (Initcall Blacklist): For kernels where the code is built-in (=y). Requires a GRUB change and a reboot.
🛠️ Included Scripts In this repository, we provide check-copy-fail.sh, which automates the audit:
Checks the current Kernel configuration (/boot/config-*).
Attempts to load the vulnerable module.
Validates whether the GRUB mitigation is present in /proc/cmdline.
⚠️ Important Notices (Disclaimer) Test Environment: Always test the mitigation in a staging environment before applying it in production.
Impact: Blocking algif_aead may affect applications that depend on the Kernel's native cryptography API (although most applications use OpenSSL or User Space libraries).
Definitive Solution: These mitigations are temporary. The definitive solution is updating the Kernel via the package manager (apt, dnf, zypper) as soon as the official patch from your distribution is released.
🤝 Contributions Feel free to open an Issue or submit a Pull Request if you find necessary variations for other distributions or improvements to the monitoring scripts.
📞 Support and Contact Developed by the Vox Cia. Team.
Website: https://voxcia.io Instagram: https://www.instagram.com/voxcia.ia/ LinkedIn: linkedin.com/company/voxcia
This material is distributed under the MIT license. Feel free to share and use it in your organization.
Tips for GitHub: Create the directories: Create the folders (Ubuntu, Rocky, etc.) and place the PDF files inside them.
Create a .txt or .md version: In addition to the PDF, it is good to have the content in text format inside GitHub so that the internal search engine indexes the commands.
LICENSE: Don't forget to add a file named LICENSE (it can be MIT or Apache 2.0) so that people know they can freely use your code.
This README is aligned with the technical content you have already produced and conveys an image of extreme seriousness.