
Detects and mitigates CVE-2026-31431, a Linux kernel local privilege escalation vulnerability, with optional PoC execution for isolated testing.
A simple, safe vulnerability scanner and mitigation tool for CVE-2026-31431 (aka "Copy Fail"), a local privilege escalation vulnerability in the Linux kernel's AF_ALG cryptographic interface.
algif_aead enabled (since ~2017)AF_ALG + splice() to corrupt page cache of setuid binaries (e.g. /usr/bin/su)# Clone or download the script
git clone https://github.com/yourusername/cve-2026-31431-checker.git
cd cve-2026-31431-checker
# Make executable
chmod +x cve-2026-31431-checker.py
sudo ./cve-2026-31431-checker.py
algif_aead module# Quick mitigation (no reboot required in most cases)
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif.conf
sudo rmmod algif_aead 2>/dev/null || true
For systems where the module is built-in, add to kernel command line:
initcall_blacklist=algif_aead_init
Update your kernel to a version containing the official patch from your distribution.
This tool is provided for defensive and educational purposes only. The author is not responsible for any damage caused by misuse of the PoC.
w01f