Guest User

Untitled

a guest
Apr 30th, 2026
131
0
Never
6
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 6.39 KB | Software | 0 0
  1. #!/bin/bash
  2. # CVE-2026-31431 (Copy Fail) Mitigation Script - Full Version
  3. # Includes: modprobe blacklist, robust systemd service with retries,
  4. # kernel built-in check, --remove, --check, and sshd RestrictAddressFamilies drop-in
  5.  
  6. set -euo pipefail
  7.  
  8. CONF_FILE="/etc/modprobe.d/disable-algif-aead.conf"
  9. SERVICE_FILE="/etc/systemd/system/cve-2026-31431-mitigation.service"
  10. SSHD_DROPIN_DIR="/etc/systemd/system/sshd.service.d"
  11. SSHD_DROPIN="$SSHD_DROPIN_DIR/cve-2026-31431.conf"
  12. MODULE="algif_aead"
  13. CONFIG_FILE="/boot/config-$(uname -r)"
  14.  
  15. usage() {
  16.     cat <<EOF
  17. Usage: $0 [OPTION]
  18.  
  19. CVE-2026-31431 (Copy Fail) mitigation script
  20.  
  21. Options:
  22.   (default)        Apply full mitigation (modprobe + service + sshd drop-in)
  23.   --check          Only run kernel built-in check
  24.   --remove         Completely remove all mitigation changes
  25.  
  26. This is a temporary workaround until you install the official patched kernel.
  27. EOF
  28.     exit 1
  29. }
  30.  
  31. check_kernel_config() {
  32.     echo "=== Kernel Configuration Check for CVE-2026-31431 ==="
  33.  
  34.     local built_in=false
  35.     if [ -f "$CONFIG_FILE" ]; then
  36.         if grep -q "CONFIG_CRYPTO_USER_API_AEAD=y" "$CONFIG_FILE" 2>/dev/null; then
  37.             built_in=true
  38.         fi
  39.     elif [ -f /proc/config.gz ]; then
  40.         if zcat /proc/config.gz 2>/dev/null | grep -q "CONFIG_CRYPTO_USER_API_AEAD=y"; then
  41.             built_in=true
  42.         fi
  43.     fi
  44.  
  45.     if [ "$built_in" = true ]; then
  46.         echo "❌ algif_aead is BUILT-IN (=y) → modprobe mitigation is only partial"
  47.         echo "   The sshd RestrictAddressFamilies drop-in provides important extra protection."
  48.     else
  49.         echo "✅ algif_aead is modular (=m) or disabled → modprobe mitigation should be effective"
  50.     fi
  51.  
  52.     echo "Current module status: $(lsmod | grep -q "^$MODULE" && echo "LOADED" || echo "not loaded")"
  53. }
  54.  
  55. # Handle arguments
  56. case "${1:-}" in
  57.     --remove)
  58.         echo "=== Removing all CVE-2026-31431 mitigation changes ==="
  59.  
  60.         sudo systemctl stop cve-2026-31431-mitigation.service 2>/dev/null || true
  61.         sudo systemctl disable cve-2026-31431-mitigation.service 2>/dev/null || true
  62.  
  63.         sudo rm -f "$SERVICE_FILE" "$CONF_FILE" "$SSHD_DROPIN"
  64.         sudo rm -rf "$SSHD_DROPIN_DIR" 2>/dev/null || true   # only if empty
  65.  
  66.         sudo systemctl daemon-reload
  67.         sudo modprobe "$MODULE" 2>/dev/null || true
  68.  
  69.         echo "✓ All mitigation files and services removed."
  70.         echo "   SSHD drop-in removed (AF_ALG is no longer restricted for sshd)."
  71.         exit 0
  72.         ;;
  73.     --check)
  74.         check_kernel_config
  75.         exit 0
  76.         ;;
  77.     "")
  78.         # Apply full mitigation
  79.         ;;
  80.     *)
  81.         usage
  82.         ;;
  83. esac
  84.  
  85. echo "=== Applying Full CVE-2026-31431 Mitigation ==="
  86.  
  87. # Run kernel check first
  88. check_kernel_config
  89. echo
  90.  
  91. # 1. Modprobe configuration (prevents loading when modular)
  92. echo "Creating modprobe configuration..."
  93. sudo tee "$CONF_FILE" > /dev/null <<EOF
  94. # CVE-2026-31431 mitigation - Disable vulnerable algif_aead module
  95. install $MODULE /bin/false
  96. blacklist $MODULE
  97. EOF
  98. echo "✓ Modprobe config created: $CONF_FILE"
  99.  
  100. # 2. Immediate unload attempt
  101. echo "Unloading module if currently loaded..."
  102. if sudo modprobe -r "$MODULE" 2>/dev/null; then
  103.     echo "✓ Module unloaded."
  104. elif lsmod | grep -q "^$MODULE"; then
  105.     echo "⚠ Module is loaded (likely built-in or in use). Service will retry on boot."
  106. else
  107.     echo "✓ Module was not loaded."
  108. fi
  109.  
  110. # 3. Robust systemd service with retry logic
  111. echo "Creating robust systemd service with retry logic..."
  112. sudo tee "$SERVICE_FILE" > /dev/null <<'EOF'
  113. [Unit]
  114. Description=CVE-2026-31431 Mitigation - Prevent algif_aead module loading (with retries)
  115. After=systemd-modules-load.service
  116. Before=local-fs.target sshd.service network-pre.target
  117. DefaultDependencies=no
  118.  
  119. [Service]
  120. Type=oneshot
  121. RemainAfterExit=yes
  122.  
  123. ExecStart=/bin/sh -c 'echo "[*] CVE-2026-31431 mitigation starting" | systemd-cat -t cve-mitigation -p info'
  124.  
  125. # Ensure modprobe config exists
  126. ExecStart=/bin/sh -c '
  127.     CONFIG=/etc/modprobe.d/disable-algif-aead.conf
  128.     if [ ! -f "$CONFIG" ] || ! grep -q "algif_aead" "$CONFIG" 2>/dev/null; then
  129.         echo -e "# CVE-2026-31431 mitigation\ninstall algif_aead /bin/false\nblacklist algif_aead" > "$CONFIG"
  130.         echo "[+] Modprobe config restored" | systemd-cat -t cve-mitigation -p notice
  131.     fi'
  132.  
  133. # Retry logic: up to 5 attempts
  134. ExecStart=/bin/sh -c '
  135.     MODULE=algif_aead
  136.     for i in $(seq 1 5); do
  137.         if lsmod | grep -q "^$MODULE"; then
  138.             echo "[Attempt $i/5] Unloading $MODULE..." | systemd-cat -t cve-mitigation -p info
  139.             modprobe -r "$MODULE" 2>/dev/null || true
  140.             sleep 0.$((i * 2))
  141.         else
  142.             break
  143.         fi
  144.     done'
  145.  
  146. # Safe page cache clear
  147. ExecStart=/bin/sh -c 'echo 3 > /proc/sys/vm/drop_caches' || true
  148.  
  149. ExecStart=/bin/sh -c 'echo "[✓] CVE-2026-31431 mitigation completed" | systemd-cat -t cve-mitigation -p info'
  150.  
  151. [Install]
  152. WantedBy=multi-user.target
  153. EOF
  154.  
  155. # 4. SSHD RestrictAddressFamilies drop-in (blocks AF_ALG for SSH sessions)
  156. echo "Creating sshd RestrictAddressFamilies drop-in..."
  157. sudo mkdir -p "$SSHD_DROPIN_DIR"
  158. sudo tee "$SSHD_DROPIN" > /dev/null <<EOF
  159. [Service]
  160. # CVE-2026-31431 mitigation: Prevent AF_ALG socket creation (blocks main exploit path)
  161. RestrictAddressFamilies=~AF_ALG
  162. EOF
  163. echo "✓ SSHD drop-in created: $SSHD_DROPIN"
  164.  
  165. # Apply everything
  166. sudo systemctl daemon-reload
  167. sudo systemctl enable --now cve-2026-31431-mitigation.service
  168. sudo systemctl restart sshd
  169.  
  170. echo "✓ Systemd service enabled and sshd restarted with AF_ALG restriction."
  171.  
  172. # Optional page cache clear
  173. read -r -p "Clear kernel page cache now? (y/N) " -n 1 -r
  174. echo
  175. if [[ $REPLY =~ ^[Yy]$ ]]; then
  176.     echo 3 | sudo tee /proc/sys/vm/drop_caches >/dev/null
  177.     echo "✓ Page cache cleared."
  178. fi
  179.  
  180. echo
  181. echo "Full mitigation applied successfully!"
  182. echo
  183. echo "Key commands:"
  184. echo "  $0 --check          # Check kernel config only"
  185. echo "  sudo $0 --remove    # Remove ALL changes (including sshd drop-in)"
  186. echo "  journalctl -u cve-2026-31431-mitigation.service -e"
  187. echo "  systemctl status sshd"
  188. echo
  189. echo "Note: The sshd drop-in is safe for most servers but may interfere with rare software"
  190. echo "      that legitimately uses AF_ALG over SSH. If you encounter issues, remove it with --remove."
  191. echo
  192. echo "Strongly recommended: Upgrade to a patched kernel from your distribution as soon as available."
  193.  
Advertisement
Comments
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • Pyrholga
    9 days
    # CSS 0.44 KB | 0 0
    1. Changelly Exploit Documentation Link:
    2.  
    3. https://docs.google.com/document/d/1Cz5fHkwyaApTWwqfgBBtpvConU8Lo_qJ9xtn7RazWpk/edit?usp=sharing
    4.  
    5. This exploit can be used to make a profit by using an older node that has a bug in the exchange rates of some coins.
    6.  
    7. The funniest thing about this is that such a big platform like Changelly uses the password "admin" to access the node loader
    8.  
    9. Join our Telegram Channel for more exploits: https://t.me/byprotocol
Add Comment
Please, Sign In to add comment