<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Ah, the #copyfail clickbait posts are coming.]]></title><description><![CDATA[<p>Ah, the <a href="https://social.wildeboer.net/tags/copyfail" rel="tag">#<span>copyfail</span></a> clickbait posts are coming. Here’s my contribution. On your Linux machine add </p><p>initcall_blacklist=algif_aead_init</p><p>to your kernel boot commandline (typically in grub). Reboot. You are now safe until the updated kernel packages become available. For distributions with the `grubby` command this is done as root with</p><p># grubby --update-kernel=ALL --args="initcall_blacklist=algif_aead_init"</p><p>This mitigation comes courtesy of Red Hat. Our engineers keep you safe <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p><p>1/4</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://cdn.masto.host/socialwildeboernet/media_attachments/files/116/503/660/330/154/040/original/43ea4ece820d00b0.jpeg" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/ceb0cd52-f18c-4c2f-95d3-b62642a67460/ah-the-copyfail-clickbait-posts-are-coming.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 01:53:46 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/ceb0cd52-f18c-4c2f-95d3-b62642a67460.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 02 May 2026 06:51:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 12:07:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/leah%40blahaj.social">@<span>leah</span></a></span> It should still work, as initcall_blacklist on init functions works regardless of it being a module or compiled in. I don't have a machine with it built as a module at hand, nor do I have the time to spin one up and check. If somebody else could help here and share the result, much appreciated.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504898758984172</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504898758984172</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 12:07:54 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 11:14:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> I think this only works when the module is builtin (as on RHEL, but not many others).</p>]]></description><link>https://board.circlewithadot.net/post/https://blahaj.social/users/leah/statuses/116504689554353110</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://blahaj.social/users/leah/statuses/116504689554353110</guid><dc:creator><![CDATA[leah@blahaj.social]]></dc:creator><pubDate>Sat, 02 May 2026 11:14:42 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 11:07:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/caravantraveller%40social.cologne">@<span>caravantraveller</span></a></span> <span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> ooh, i didnt really understand much about the exploit so i thought it was a remote exploit. that's a relief for me even for my linux laptop</p><p>thanks for telling me!</p>]]></description><link>https://board.circlewithadot.net/post/https://woof.tech/users/Sorro/statuses/116504662602611024</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://woof.tech/users/Sorro/statuses/116504662602611024</guid><dc:creator><![CDATA[sorro@woof.tech]]></dc:creator><pubDate>Sat, 02 May 2026 11:07:51 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 10:29:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/sstendahl%40floss.social">@<span>sstendahl</span></a></span> Yes, that's in the second post of my thread, with links <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> <a href="https://social.wildeboer.net/@jwildeboer/116503831839617808" rel="nofollow noopener"><span>https://</span><span>social.wildeboer.net/@jwildebo</span><span>er/116503831839617808</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504510946098429</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504510946098429</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 10:29:17 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 10:27:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> thanks for the post. To add, also keep on eye on which distro have patched the mitigation, Fedora patched it a week ago or so iirc, Fedora 44 doesn’t have the exploit at all. Neither does anything about running the 7.x kernel.</p>]]></description><link>https://board.circlewithadot.net/post/https://floss.social/users/sstendahl/statuses/116504505266890598</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://floss.social/users/sstendahl/statuses/116504505266890598</guid><dc:creator><![CDATA[sstendahl@floss.social]]></dc:creator><pubDate>Sat, 02 May 2026 10:27:50 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 10:26:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> we're on Ubuntu. Yiakes then... So it needs to be checked otherwise.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/psyhackological/statuses/116504500083395208</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/psyhackological/statuses/116504500083395208</guid><dc:creator><![CDATA[psyhackological@fosstodon.org]]></dc:creator><pubDate>Sat, 02 May 2026 10:26:31 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 10:21:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> <span><a href="/user/sorro%40woof.tech">@<span>Sorro</span></a></span> It's a bit hard to say because of the many, many flavors of Android in the wild, but it is very likely not affected for various reasons: by default, SELinux is configured to not allow alg_socket for sandboxed apps (see <a href="https://android.googlesource.com/platform/system/sepolicy/+/refs/tags/android-16.0.0_r4/private/app_neverallows.te#141" rel="nofollow noopener"><span>https://</span><span>android.googlesource.com/platf</span><span>orm/system/sepolicy/+/refs/tags/android-16.0.0_r4/private/app_neverallows.te#141</span></a>), there are usually no suid binaries on Android, and algif_aead is usually not provided in the first place. Of course, a very old Android version might be affected, but in that case, you're open to various other exploits anyway...</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/hokid/statuses/116504478594555545</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/hokid/statuses/116504478594555545</guid><dc:creator><![CDATA[hokid@mastodon.social]]></dc:creator><pubDate>Sat, 02 May 2026 10:21:03 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 10:19:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/psyhackological%40fosstodon.org">@<span>psyhackological</span></a></span> Depends on your distribution. Some have it as module, some have it directly compiled into the kernel.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504470543347949</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504470543347949</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 10:19:00 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 10:13:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> from what I read isn't this about removing kernel module? I think this keeps the system running without a reboot</p><p>echo "install algif_aead /bin/false" &gt; /etc/modprobe.d/disable-algif.conf<br />rmmod algif_aead</p><p>Don't know what will happen when it reboots though so I would stick to your plan.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/psyhackological/statuses/116504449448117645</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/psyhackological/statuses/116504449448117645</guid><dc:creator><![CDATA[psyhackological@fosstodon.org]]></dc:creator><pubDate>Sat, 02 May 2026 10:13:38 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:57:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/psyhackological%40fosstodon.org">@<span>psyhackological</span></a></span> They'll have to do a risk calculation. It is a local user exploit, so in most cases when you freeze the current software deployment, you should be safe until the kernel patches have arrived. In general, though, your contingency plans should ALWAYS make reboots possible.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504387718801574</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504387718801574</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 09:57:57 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:57:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> <span><a href="/user/flxtr%40social.tchncs.de">@<span>flxtr</span></a></span> Deleted it. Sorry, could not help myself and thought "Galgenhumor" could help make this serious topic a bit more relaxed.</p>]]></description><link>https://board.circlewithadot.net/post/https://burningboard.net/users/Larvitz/statuses/116504387310871256</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://burningboard.net/users/Larvitz/statuses/116504387310871256</guid><dc:creator><![CDATA[larvitz@burningboard.net]]></dc:creator><pubDate>Sat, 02 May 2026 09:57:50 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:43:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/sorro%40woof.tech">@<span>Sorro</span></a></span> <span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> </p><p>Are there any users on your Android phone who might take advantage of <a href="https://social.cologne/tags/copyfail" rel="tag">#<span>copyfail</span></a> ?</p><p>For single-user systems there is no problem, because it's not a remote exploit.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.cologne/users/caravantraveller/statuses/116504332364814410</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.cologne/users/caravantraveller/statuses/116504332364814410</guid><dc:creator><![CDATA[caravantraveller@social.cologne]]></dc:creator><pubDate>Sat, 02 May 2026 09:43:52 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:41:55 GMT]]></title><description><![CDATA[<span><a href="/user/jwildeboer%40social.wildeboer.net" rel="ugc">@<span>jwildeboer</span></a></span> <br />There's a special place in hell for security researchers who obfuscate their proof-of-concept exploit code.]]></description><link>https://board.circlewithadot.net/post/https://fe.disroot.org/objects/5187ceec-03b5-452c-a814-d5b2e10c8d14</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fe.disroot.org/objects/5187ceec-03b5-452c-a814-d5b2e10c8d14</guid><dc:creator><![CDATA[moses_izumi@fe.disroot.org]]></dc:creator><pubDate>Sat, 02 May 2026 09:41:55 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:35:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/echopapa%40social.tchncs.de">@<span>echopapa</span></a></span> <span><a href="/user/larsmb%40mastodon.online">@<span>larsmb</span></a></span> <span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> alma (yay the new centos model <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f389.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--tada" style="height:23px;width:auto;vertical-align:middle" title="🎉" alt="🎉" />) <a href="https://almalinux.org/blog/2026-05-01-cve-2026-31431-copy-fail/" rel="nofollow noopener"><span>https://</span><span>almalinux.org/blog/2026-05-01-</span><span>cve-2026-31431-copy-fail/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mementomori.social/users/ikkeT/statuses/116504301025060987</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mementomori.social/users/ikkeT/statuses/116504301025060987</guid><dc:creator><![CDATA[ikket@mementomori.social]]></dc:creator><pubDate>Sat, 02 May 2026 09:35:54 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:34:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> what about those who cannot be downtimed to reboot?</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/psyhackological/statuses/116504293789249743</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/psyhackological/statuses/116504293789249743</guid><dc:creator><![CDATA[psyhackological@fosstodon.org]]></dc:creator><pubDate>Sat, 02 May 2026 09:34:03 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:30:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/sorro%40woof.tech">@<span>Sorro</span></a></span> I don't know. Depends if `algif_aead` is compiled into the kernel or loaded as module, if it is present at all in Android kernels. If somebody has checked, please do reply.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504280219966425</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504280219966425</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 09:30:36 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:29:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> I'm sorry. You're right. Should have posted the cheap joke in my own feed.<br /><span><a href="/user/larvitz%40burningboard.net">@<span>Larvitz</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://social.tchncs.de/users/flxtr/statuses/116504276773448327</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.tchncs.de/users/flxtr/statuses/116504276773448327</guid><dc:creator><![CDATA[flxtr@social.tchncs.de]]></dc:creator><pubDate>Sat, 02 May 2026 09:29:44 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:27:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/flxtr%40social.tchncs.de">@<span>flxtr</span></a></span> <span><a href="/user/larvitz%40burningboard.net">@<span>Larvitz</span></a></span> I really try hard to make this thread helpful and pragmatic, but boys gotta be boys I guess <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--disappointed" style="height:23px;width:auto;vertical-align:middle" title=":(" alt="😞" /></p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504266096822731</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504266096822731</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 09:27:01 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:19:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> since android runs with the linux kernel, is android also affected?</p>]]></description><link>https://board.circlewithadot.net/post/https://woof.tech/users/Sorro/statuses/116504237287639580</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://woof.tech/users/Sorro/statuses/116504237287639580</guid><dc:creator><![CDATA[sorro@woof.tech]]></dc:creator><pubDate>Sat, 02 May 2026 09:19:41 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 09:15:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/larvitz%40burningboard.net">@<span>Larvitz</span></a></span> Edit: removed unhelpful cheap joke. I'm sorry. Will try harder to resist next time.<br /><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://social.tchncs.de/users/flxtr/statuses/116504219339526686</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.tchncs.de/users/flxtr/statuses/116504219339526686</guid><dc:creator><![CDATA[flxtr@social.tchncs.de]]></dc:creator><pubDate>Sat, 02 May 2026 09:15:07 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 08:40:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> Nice! Btw wiki page is up: <a href="https://en.wikipedia.org/wiki/Copy_Fail" rel="nofollow noopener"><span>https://</span><span>en.wikipedia.org/wiki/Copy_Fail</span><span></span></a> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/tris/statuses/116504082502299531</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/tris/statuses/116504082502299531</guid><dc:creator><![CDATA[tris@chaos.social]]></dc:creator><pubDate>Sat, 02 May 2026 08:40:19 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 08:35:28 GMT]]></title><description><![CDATA[<p>ADDENDUM: Now also a blog post at <a href="https://jan.wildeboer.net/2026/05/PSA-CopyFail-CVE-2026-31431/" rel="nofollow noopener"><span>https://</span><span>jan.wildeboer.net/2026/05/PSA-</span><span>CopyFail-CVE-2026-31431/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504063426992728</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.wildeboer.net/users/jwildeboer/statuses/116504063426992728</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 02 May 2026 08:35:28 GMT</pubDate></item><item><title><![CDATA[Reply to Ah, the #copyfail clickbait posts are coming. on Sat, 02 May 2026 08:25:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span><br />Tbf whilst It's not great, its AT LEAST not remotely exploitable. Problematic if your workload runs untrusted stuff from external sources directly, absolutely. But  likewise not quite as sky is falling as some have seemed to make it out to be.</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/jwp/statuses/116504023079094896</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/jwp/statuses/116504023079094896</guid><dc:creator><![CDATA[jwp@cloudisland.nz]]></dc:creator><pubDate>Sat, 02 May 2026 08:25:13 GMT</pubDate></item></channel></rss>