This script will attempt to mitigate the copy_fail attack. CVE-2026-31431
A bash script for mitigating linux dirty frag exploit CVE-2026-43500
A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940
Dirty Frag (CVE-2026-43284/43500) - Linux Kernel LPE Deep Technical Analysis by Bomb
Exploiting Parsec for Windows to gain SYSTEM privileges
Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)
Linux Kernel Local Privilege Escalation
Kernel LPE PoC & Mitigation Toolkit - ROSN-LR5-Full (CVE-2026-31431)
Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security research only.
Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write
Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.
Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE
Runtime integrity guard that detects and blocks Linux page cache tampering attacks (Copy Fail CVE-2026-31431, Dirty Pipe, Dirty COW) at execution time. Uses fanotify + O_DIRECT to protect SUID/SGID binaries from privilege escalation via page cache corruption.
CVE-2026-31431 ("Copy Fail") vulnerability detector & exploit
CVE-2026-31431 in C for aarch64 and amd64
Paranoid disable Linux IPsec ESP support (esp4/esp6) and RxRPC support.
CVE-2022-30190 — "Follina" — MSDT remote code execution via Word docs, no macro needed, Defender initially missed it
PoC and advisory for CVE-2026-44648