Copy Fail Lpe Mitigation

Linux kernel local privilege escalation (LPE) incident response and runtime mitigation. Use whenever the user asks about CVE-2026-31431 ("Copy Fail"), AF_ALG / algif_aead exploitation, bpf-lsm runtime kernel mitigations, eBPF-based socket visibility/enforcement, page-cache poisoning via in-place crypto, or the general pattern of no-reboot LPE containment on a large Linux fleet. Also trigger for: "how do I block AF_ALG without rebooting", "bpf-lsm allowlist socket", "kernel module mitigation without rmmod", "fleet-wide eBPF socket tracing", "authencesn OOB write", or any request to replicate Cloudflare's staged visibility-then-enforcement rollout methodology.

daedalus d7776c0 9.2 KB Updated

File contents

daedalus/skills/tree/main/skills/copy-fail-reponse commit d7776c09c9

Frequently asked questions

npx skillmds@latest add daedalus/copy-fail-lpe-mitigation