Copy Fail (CVE-2026-31431): the modprobe.d + rmmod recipe everyone is sharing does nothing on RHEL/Alma/Rocky/Oracle. They ship algif_aead built in. On Debian/Ubuntu it auto-loads when anything binds AF_ALG — no default protection. PoC fails on Busybox/Alpine but still vulnerable. Details below.
How to block CVE-2026-31431 (Copy Fail) - secwest.net - secure virtual engagement
How to block CVE-2026-31431 (Copy Fail) — the Linux kernel algif_aead local privilege escalation that poisons setuid binaries via the shared page cache. Fleet-scale module disable, RHEL built-in worka...
secwest.net