Zurück zu den Sicherheitshinweisen

Mitigations for CopyFail linux local privilege escalation vulnerability

CopyFail (CVE-2026-31431) is a Linux local privilege escalation that affects nearly all systems and lets a local user gain root. DirectAdmin has published immediate mitigations to hold the line until distribution hot-fixes land: blacklist and unload the algif_aead kernel module on Debian/Ubuntu, or disable it at boot via initcall_blacklist on RHEL-based systems.

Critical 7.8 CVSS Aktiv ausgenutzt
DirectAdmin

Was das unter einer SharedLicense-Lizenz bedeutet

A local user can escalate to root on almost any affected system, so shared hosting servers are exposed to every hosted account until the kernel is fixed or mitigated.

A new local privilege escalation vulnerability named CopyFail CVE-2026-31431 was recently disclosed. It affects almost all of the systems and allows local user to get root access on the system. The Linux distribution maintainers are busy with releasing hot-fixes.

We are sharing an immediate mitigation for server administrators until we receive a fix from upstream.

For Debian, Ubuntu (and other Debian) based systems, the exploitable code is in a separate kernel module. So it is enough to just blacklist this module and unload it if it is already loaded. Commands:

echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
rmmod algif_aead 2>/dev/null

For RHEL based systems, the explotable code is built-in. It can be disabled with extra kernel boot parameter and requires a server restart. Commands:

echo 'GRUB_CMDLINE_LINUX_DEFAULT="${GRUB_CMDLINE_LINUX_DEFAULT} initcall_blacklist=algif_aead_init"' >> /etc/default/grub
grub2-mkconfig -o /etc/grub2.cfg
grubby --args initcall_blacklist=algif_aead_init --update-kernel=ALL --no-etc-grub-update
reboot

Note: the double approach first changing /etc/default/grub and then directly with grubby is to make sure same set of commands works on all RHEL systems and the change is persistent. The grubby command alone is enough to update the kernel arguments but they would be lost on the next kernel update.

Häufig gestellte Fragen

What is CopyFail (CVE-2026-31431)?
It is a recently disclosed Linux local privilege escalation that allows a local user to gain root access. DirectAdmin notes it affects almost all systems while distribution maintainers prepare hot-fixes.
What is the immediate mitigation for CopyFail on Debian or Ubuntu?
Blacklist and unload the affected kernel module: run echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf and then rmmod algif_aead 2>/dev/null. The exploitable code lives in that separate module on Debian-based systems.
What is the mitigation on RHEL-based systems?
The exploitable code is built into the kernel, so disable it at boot: add initcall_blacklist=algif_aead_init to GRUB_CMDLINE_LINUX_DEFAULT in /etc/default/grub, regenerate the config with grub2-mkconfig -o /etc/grub2.cfg (or use grubby --args initcall_blacklist=algif_aead_init), and restart the server.
When will a real fix for CVE-2026-31431 be available?
Linux distribution maintainers were already releasing hot-fixes when DirectAdmin published the mitigations. Apply the mitigation now, then update the kernel as soon as your distribution ships the fixed version.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen