Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/bash
- # CVE-2026-31431 (Copy Fail) Mitigation Script - Full Version
- # Includes: modprobe blacklist, robust systemd service with retries,
- # kernel built-in check, --remove, --check, and sshd RestrictAddressFamilies drop-in
- set -euo pipefail
- CONF_FILE="/etc/modprobe.d/disable-algif-aead.conf"
- SERVICE_FILE="/etc/systemd/system/cve-2026-31431-mitigation.service"
- SSHD_DROPIN_DIR="/etc/systemd/system/sshd.service.d"
- SSHD_DROPIN="$SSHD_DROPIN_DIR/cve-2026-31431.conf"
- MODULE="algif_aead"
- CONFIG_FILE="/boot/config-$(uname -r)"
- usage() {
- cat <<EOF
- Usage: $0 [OPTION]
- CVE-2026-31431 (Copy Fail) mitigation script
- Options:
- (default) Apply full mitigation (modprobe + service + sshd drop-in)
- --check Only run kernel built-in check
- --remove Completely remove all mitigation changes
- This is a temporary workaround until you install the official patched kernel.
- EOF
- exit 1
- }
- check_kernel_config() {
- echo "=== Kernel Configuration Check for CVE-2026-31431 ==="
- local built_in=false
- if [ -f "$CONFIG_FILE" ]; then
- if grep -q "CONFIG_CRYPTO_USER_API_AEAD=y" "$CONFIG_FILE" 2>/dev/null; then
- built_in=true
- fi
- elif [ -f /proc/config.gz ]; then
- if zcat /proc/config.gz 2>/dev/null | grep -q "CONFIG_CRYPTO_USER_API_AEAD=y"; then
- built_in=true
- fi
- fi
- if [ "$built_in" = true ]; then
- echo "❌ algif_aead is BUILT-IN (=y) → modprobe mitigation is only partial"
- echo " The sshd RestrictAddressFamilies drop-in provides important extra protection."
- else
- echo "✅ algif_aead is modular (=m) or disabled → modprobe mitigation should be effective"
- fi
- echo "Current module status: $(lsmod | grep -q "^$MODULE" && echo "LOADED" || echo "not loaded")"
- }
- # Handle arguments
- case "${1:-}" in
- --remove)
- echo "=== Removing all CVE-2026-31431 mitigation changes ==="
- sudo systemctl stop cve-2026-31431-mitigation.service 2>/dev/null || true
- sudo systemctl disable cve-2026-31431-mitigation.service 2>/dev/null || true
- sudo rm -f "$SERVICE_FILE" "$CONF_FILE" "$SSHD_DROPIN"
- sudo rm -rf "$SSHD_DROPIN_DIR" 2>/dev/null || true # only if empty
- sudo systemctl daemon-reload
- sudo modprobe "$MODULE" 2>/dev/null || true
- echo "✓ All mitigation files and services removed."
- echo " SSHD drop-in removed (AF_ALG is no longer restricted for sshd)."
- exit 0
- ;;
- --check)
- check_kernel_config
- exit 0
- ;;
- "")
- # Apply full mitigation
- ;;
- *)
- usage
- ;;
- esac
- echo "=== Applying Full CVE-2026-31431 Mitigation ==="
- # Run kernel check first
- check_kernel_config
- echo
- # 1. Modprobe configuration (prevents loading when modular)
- echo "Creating modprobe configuration..."
- sudo tee "$CONF_FILE" > /dev/null <<EOF
- # CVE-2026-31431 mitigation - Disable vulnerable algif_aead module
- install $MODULE /bin/false
- blacklist $MODULE
- EOF
- echo "✓ Modprobe config created: $CONF_FILE"
- # 2. Immediate unload attempt
- echo "Unloading module if currently loaded..."
- if sudo modprobe -r "$MODULE" 2>/dev/null; then
- echo "✓ Module unloaded."
- elif lsmod | grep -q "^$MODULE"; then
- echo "⚠ Module is loaded (likely built-in or in use). Service will retry on boot."
- else
- echo "✓ Module was not loaded."
- fi
- # 3. Robust systemd service with retry logic
- echo "Creating robust systemd service with retry logic..."
- sudo tee "$SERVICE_FILE" > /dev/null <<'EOF'
- [Unit]
- Description=CVE-2026-31431 Mitigation - Prevent algif_aead module loading (with retries)
- After=systemd-modules-load.service
- Before=local-fs.target sshd.service network-pre.target
- DefaultDependencies=no
- [Service]
- Type=oneshot
- RemainAfterExit=yes
- ExecStart=/bin/sh -c 'echo "[*] CVE-2026-31431 mitigation starting" | systemd-cat -t cve-mitigation -p info'
- # Ensure modprobe config exists
- ExecStart=/bin/sh -c '
- CONFIG=/etc/modprobe.d/disable-algif-aead.conf
- if [ ! -f "$CONFIG" ] || ! grep -q "algif_aead" "$CONFIG" 2>/dev/null; then
- echo -e "# CVE-2026-31431 mitigation\ninstall algif_aead /bin/false\nblacklist algif_aead" > "$CONFIG"
- echo "[+] Modprobe config restored" | systemd-cat -t cve-mitigation -p notice
- fi'
- # Retry logic: up to 5 attempts
- ExecStart=/bin/sh -c '
- MODULE=algif_aead
- for i in $(seq 1 5); do
- if lsmod | grep -q "^$MODULE"; then
- echo "[Attempt $i/5] Unloading $MODULE..." | systemd-cat -t cve-mitigation -p info
- modprobe -r "$MODULE" 2>/dev/null || true
- sleep 0.$((i * 2))
- else
- break
- fi
- done'
- # Safe page cache clear
- ExecStart=/bin/sh -c 'echo 3 > /proc/sys/vm/drop_caches' || true
- ExecStart=/bin/sh -c 'echo "[✓] CVE-2026-31431 mitigation completed" | systemd-cat -t cve-mitigation -p info'
- [Install]
- WantedBy=multi-user.target
- EOF
- # 4. SSHD RestrictAddressFamilies drop-in (blocks AF_ALG for SSH sessions)
- echo "Creating sshd RestrictAddressFamilies drop-in..."
- sudo mkdir -p "$SSHD_DROPIN_DIR"
- sudo tee "$SSHD_DROPIN" > /dev/null <<EOF
- [Service]
- # CVE-2026-31431 mitigation: Prevent AF_ALG socket creation (blocks main exploit path)
- RestrictAddressFamilies=~AF_ALG
- EOF
- echo "✓ SSHD drop-in created: $SSHD_DROPIN"
- # Apply everything
- sudo systemctl daemon-reload
- sudo systemctl enable --now cve-2026-31431-mitigation.service
- sudo systemctl restart sshd
- echo "✓ Systemd service enabled and sshd restarted with AF_ALG restriction."
- # Optional page cache clear
- read -r -p "Clear kernel page cache now? (y/N) " -n 1 -r
- echo
- if [[ $REPLY =~ ^[Yy]$ ]]; then
- echo 3 | sudo tee /proc/sys/vm/drop_caches >/dev/null
- echo "✓ Page cache cleared."
- fi
- echo
- echo "Full mitigation applied successfully!"
- echo
- echo "Key commands:"
- echo " $0 --check # Check kernel config only"
- echo " sudo $0 --remove # Remove ALL changes (including sshd drop-in)"
- echo " journalctl -u cve-2026-31431-mitigation.service -e"
- echo " systemctl status sshd"
- echo
- echo "Note: The sshd drop-in is safe for most servers but may interfere with rare software"
- echo " that legitimately uses AF_ALG over SSH. If you encounter issues, remove it with --remove."
- echo
- echo "Strongly recommended: Upgrade to a patched kernel from your distribution as soon as available."
Advertisement