# Mitigating Copy Fail, Dirty Frag and the DirectAdmin 1.711 TLS privilege escalation

Source: https://srvscripts.com/guides/directadmin-1-711-tls-privilege-escalation/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Shared hosting servers give untrusted code a local shell, in effect, through PHP, cron and SSH. A local privilege escalation in the kernel or in the panel is therefore a full compromise, not a theoretical one. 2026 has produced three kernel LPEs that matter on every DirectAdmin host, plus a privilege escalation in DirectAdmin’s own new TLS system that 1.711 fixed on 2026-09-22. This guide applies all four mitigations and shows how to confirm each one.

In short: Update DirectAdmin to 1.711 or later with da update, block the algif_aead, esp4, esp6 and rxrpc modules with install … /bin/false lines under /etc/modprobe.d/, and apply the fixed distribution kernel or a KernelCare patch.

**Short answer:** Update DirectAdmin to 1.711 or later with `da update`, block the `algif_aead`, `esp4`, `esp6` and `rxrpc` modules with `install ... /bin/false` lines under `/etc/modprobe.d/`, and apply the fixed distribution kernel or a KernelCare patch. Then confirm with `lsmod`, `modprobe -n -v` and `da version` after a reboot that none of the modules load and the panel is on the fixed release.

## Update DirectAdmin first

The TLS-system flaw allowed a local user to escalate through the certificate provisioning path added in 1.706. The fix is in 1.711 and there is no configuration workaround, so the first step on any server running 1.706 to 1.710 is the update:

```
da version
da update
systemctl restart directadmin
```

Servers on the stable channel with automatic updates on will already have it; confirm rather than assume. If `da update` fails, [DirectAdmin license errors and update failures](/guides/directadmin-license-error-update-failures/) covers the causes.

## Copy Fail (CVE-2026-31431)

Disclosed on 2026-04-29, Copy Fail abuses the `algif_aead` kernel module, part of the userspace crypto API. Nothing on a hosting server uses that interface, so the mitigation is to prevent the module from loading and to remove it if loaded:

```
echo 'install algif_aead /bin/false' > /etc/modprobe.d/copyfail.conf
rmmod algif_aead 2>/dev/null
lsmod | grep algif
```

The `install` line makes any future load attempt run `/bin/false` instead. Because the module can also be pulled in at boot, add the initcall blacklist to the kernel command line as a second layer:

```
grubby --update-kernel=ALL --args='initcall_blacklist=algif_aead_init'
```

On Debian and Ubuntu, add the parameter to `GRUB_CMDLINE_LINUX` in `/etc/default/grub` and run `update-grub`. The parameter takes effect at the next reboot; the modprobe rule takes effect immediately.

## Dirty Frag (CVE-2026-43284 and CVE-2026-43500)

Disclosed on 2026-05-07 and exploited in the wild soon after, Dirty Frag involves the xfrm ESP path and the RxRPC socket family. Hosting servers do not need either unless they terminate IPsec tunnels or use AFS. Blacklist all three modules:

```
cat > /etc/modprobe.d/dirtyfrag.conf  /etc/sysctl.d/99-lpe-hardening.conf
