Skip to main content
Run any Skill in Manus
with one click

page-cache-lpe-mitigation

Stars1
Forks0
UpdatedMay 7, 2026 at 22:58

Linux kernel local privilege escalation (LPE) incident response and runtime mitigation. Use whenever the user asks about CVE-2026-31431 ("Copy Fail"), "Dirty Frag" (xfrm-ESP + RxRPC page-cache write, no CVE yet), AF_ALG / algif_aead exploitation, xfrm ESP in-place decryption, rxkad/RxRPC pcbc write, bpf-lsm runtime kernel mitigations, eBPF-based socket visibility/enforcement, page-cache poisoning via in-place crypto, or the general pattern of no-reboot LPE containment on a large Linux fleet. Also trigger for: "how do I block AF_ALG without rebooting", "block esp4 esp6 rxrpc modules", "bpf-lsm allowlist socket", "kernel module mitigation without rmmod", "fleet-wide eBPF socket tracing", "authencesn OOB write", "fcrypt brute-force userspace key", "skb_cow_data bypass", or any request to replicate Cloudflare's staged visibility-then-enforcement rollout methodology. Covers the entire page-cache-poison LPE family: Dirty Pipe → Copy Fail → Dirty Frag.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly