Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Detections-CVE-2026-31431 — CVE-2026-31431 LinuxカーネルLPE脆弱性(Copy Fail)の検出ルール、YARAシグネチャ、auditd/Wazuhルール、MISPイベントテンプレート。IoCs、緩和策、エクスプロイト分析を含む。 | Kitploit
ツール/GitHubGitHub/insomnisec/detections-cve-2026-31431
侵害指標 (IOC) 管理特権昇格脆弱性分析エクスプロイトフォレンジック脅威インテリジェンス侵入検知学習と教育インシデントレスポンス

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHubinsomnisec/detections-cve-2026-31431

Detections-CVE-2026-31431

CVE-2026-31431 LinuxカーネルLPE脆弱性(Copy Fail)の検出ルール、YARAシグネチャ、auditd/Wazuhルール、MISPイベントテンプレート。IoCs、緩和策、エクスプロイト分析を含む。

リポジトリを見る
2114ヶ月前未レビュー

移動先: https://github.com/insomnisec/public_cve_detections

検出パブリケーションの長期的な管理を向上させるため

このリポジトリは2026年6月に削除されます

今後はもう一方のリポジトリを使用してください

CVE-2026-31431 "Copy Fail" — 検出・対応パッケージ

公開日: 2026-04-30
CVSSv3: 7.8 (高)
種別: ローカル権限昇格 (LPE)
サブシステム: Linuxカーネルの algif_aead / authencesn 暗号テンプレート
影響を受ける範囲: Linuxカーネル 4.14 – 6.18.21(2017年以降のほぼすべてのディストリビューション)
参考情報:

  • Xint/Theori Write-up
  • 公式PoC
  • oss-security の開示
  • copy.fail

目次

  1. 脆弱性概要
  2. エクスプロイトの仕組み
  3. 検出の制限事項
  4. 緊急緩和策
  5. YARAルール
  6. Auditdルール
  7. Wazuhルール
  8. MISPイベントテンプレート
  9. パッチ適用と修復
  10. 主要なIoCsリファレンス

脆弱性概要

CVE-2026-31431 は、カーネル 4.14(2017年)で導入された論理上の欠陥であり、3つの独立した変更が交差する地点に存在します。

  1. authencesn テンプレート(IPsec ESNサポート用に2011年追加)は、出力バッファの境界を越えてスクラッチデータ4バイトを書き込みます。
  2. AF_ALG は2015年にAEADサポートを獲得し、ユーザー空間がページキャッシュされたファイルから splice() でデータを送信できるようになりました。
  3. 2017年、algif_aead.c はインプレースで動作する(req->src == req->dst)ように最適化され、ライブなページキャッシュページを書き込み可能なscatterlistに配置しました。

その結果、非特権ユーザーは、読み取り可能な任意のファイル(setuidバイナリや /etc/passwd を含む)のカーネルのページキャッシュコピーに、攻撃者が制御する4バイトを正確に書き込むことができます — ディスク上のファイルには触れずに。動作するPoCは732バイトのPythonスクリプトです。レースコンディションは発生しません。ディストリビューションごとのオフセットも不要です。Ubuntu、RHEL、Amazon Linux、SUSE で確実に動作します。


エクスプロイトの仕組み```

Attacker opens AF_ALG socket (family 38, type 5) └─ Binds to "authencesn(hmac(sha256),cbc(aes))" └─ Sets SOL_ALG (279) options including key and authsize └─ Accepts a connection socket

Attacker opens target file (e.g., /etc/passwd) read-only └─ Uses splice() to feed page-cache pages into the AEAD socket's RX buffer └─ Sends crafted AAD via sendmsg() — bytes 4–7 of AAD = attacker-controlled write value

authencesn performs in-place decryption: └─ scatterwalk_map_and_copy writes seqno_lo into the chained page-cache page └─ recvmsg() returns an error (HMAC fails — expected), but the write already happened

Page-cache now contains attacker-modified copy of the file └─ Kernel executes from page-cache, not disk └─ On-disk file is UNCHANGED — file integrity tools see nothing

The PoC targets `/etc/passwd`: it finds the offset of the running user's UID field and overwrites it with `0000`, then invokes `su` to obtain a root shell.

---

## Detection Limitations

> **Read this section before deploying any rules below.**

This exploit has two properties that significantly limit detection coverage:

**1. The write goes to the page cache, not the filesystem.**
Any detection tool that monitors file system events — `inotify`, `fanotify`, AIDE, Tripwire, auditd path watches — will **not** observe the modification. The on-disk file is never written. This means the `-p w` (write) flags in auditd path watches for `/usr/bin/su` or `/etc/passwd` will not catch the actual exploitation write.

**2. The mechanism uses legitimate kernel interfaces.**
`AF_ALG` sockets, `splice()`, and `authencesn` all have legitimate uses (IPsec, kernel self-tests, sendfile-style I/O). Detection must focus on the *combination* of these primitives rather than any one in isolation, and false positives should be expected on systems running IPsec or doing kernel crypto testing.

**What detection CAN catch:**
- The `socket(AF_ALG, SOCK_SEQPACKET, 0)` syscall
- The `splice()` syscall correlated with the above, especially near setuid binary access
- The PoC script itself (via YARA)
- The specific `authencesn(hmac(sha256),cbc(aes))` algorithm string in process memory or script files

**What detection CANNOT catch:**
- The actual page-cache write (in-memory, no filesystem event)
- Post-exploitation use of the modified page-cache entry (looks like a normal `su` or `passwd` call)
- Variants that avoid Python or the specific algorithm string

---

## Immediate Mitigation

Before deploying detection rules, apply this mitigation on any unpatched host:```bash
# Disable algif_aead kernel module — blocks the exploit primitive entirely
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif-aead.conf
sudo rmmod algif_aead 2>/dev/null || true

緩和策が有効であることを確認するには、公式ディテクターを使用します:```bash

Exit 0 = not vulnerable / mitigated

Exit 2 = VULNERABLE

python3 test_cve_2026_31431.py

> **注記:** `rmmod` コマンドは、モジュールが現在ロードされていない場合に失敗しますが、これは許容されます。`modprobe.d` 設定により、今後のロードが防止されます。この緩和策は、標準的なTLS、SSH、ファイルシステム暗号化のワークロードには影響しません — `authencesn` テンプレートを使用する拡張シーケンス番号付きIPsecにのみ影響します。これは、専用VPNゲートウェイ以外では一般的ではありません。

---

## YARAルール

`cve_2026_31431.yar` として保存

> **スキャン範囲:** このルールは、ディスク上またはメモリダンプから取得したPythonスクリプトファイルをスキャンするように設計されています。既知のPoCおよび類似の変種に一致します。syscallレベルでの悪用活動は検出しません — それにはauditd/Wazuhルールを使用してください。```yara
rule CVE_2026_31431_CopyFail_PoC_HighConfidence {
    meta:
        description     = "High-confidence match: CVE-2026-31431 Copy Fail PoC or close variant"
        author          = "Detection Engineering"
        reference       = "https://xint.io/blog/copy-fail-linux-distributions"
        cve             = "CVE-2026-31431"
        date            = "2026-04-30"
        severity        = "High"
        cvss            = "7.8"

    strings:
        // Algorithm string unique to this exploit path — very high fidelity
        $alg_full      = "authencesn(hmac(sha256),cbc(aes))" ascii

        // Specific socket call signature from PoC: AF_ALG=38, SOCK_SEQPACKET=5
        $socket_call   = "socket(38,5,0)" ascii

        // SOL_ALG socket option (decimal 279)
        $solalg        = "setsockopt(279" ascii

        // Hex key/iv payload written via setsockopt in PoC
        $key_payload   = "0800010000000010" ascii

        // splice() usage in context of AEAD operations
        $splice        = "splice(" ascii

        // Target indicators from PoC (page-cache corruption targets)
        $target_passwd = "/etc/passwd" ascii
        $target_su     = "/usr/bin/su" ascii

        // AF_ALG aead bind strings
        $aead_bind     = "\"aead\"" ascii

    condition:
        // High-confidence: unique algorithm string alone is sufficient
        $alg_full
        or
        // Medium-confidence: socket primitive + option number
        ($socket_call and $solalg)
        or
        // Medium-confidence: splice into AEAD socket targeting a setuid path
        ($aead_bind and $splice and ($target_passwd or $target_su))
        or
        // PoC hex payload present alongside splice
        ($key_payload and $splice)
}

rule CVE_2026_31431_CopyFail_Mechanism {
    meta:
        description     = "Behavioral: AF_ALG AEAD + splice combination suggestive of CVE-2026-31431 technique"
        author          = "Detection Engineering"
        reference       = "https://xint.io/blog/copy-fail-linux-distributions"
        cve             = "CVE-2026-31431"
        date            = "2026-04-30"
        severity        = "Medium"
        note            = "Higher false positive rate than HighConfidence rule — review matches in context"

    strings:
        $authencesn    = "authencesn" ascii nocase
        $af_alg_num    = "socket(38" ascii
        $sol_alg_num   = "279" ascii
        $splice        = "splice(" ascii

    condition:
        ($authencesn and $splice)
        or
        ($af_alg_num and $sol_alg_num and $splice)
}

Auditd ルール

/etc/audit/rules.d/cve-2026-31431.rules として保存

ツールをダウンロード