
CVE-2026-31431 LinuxカーネルLPE脆弱性(Copy Fail)の検出ルール、YARAシグネチャ、auditd/Wazuhルール、MISPイベントテンプレート。IoCs、緩和策、エクスプロイト分析を含む。
公開日: 2026-04-30
CVSSv3: 7.8 (高)
種別: ローカル権限昇格 (LPE)
サブシステム: Linuxカーネルの algif_aead / authencesn 暗号テンプレート
影響を受ける範囲: Linuxカーネル 4.14 – 6.18.21(2017年以降のほぼすべてのディストリビューション)
参考情報:
CVE-2026-31431 は、カーネル 4.14(2017年)で導入された論理上の欠陥であり、3つの独立した変更が交差する地点に存在します。
authencesn テンプレート(IPsec ESNサポート用に2011年追加)は、出力バッファの境界を越えてスクラッチデータ4バイトを書き込みます。AF_ALG は2015年にAEADサポートを獲得し、ユーザー空間がページキャッシュされたファイルから splice() でデータを送信できるようになりました。algif_aead.c はインプレースで動作する(req->src == req->dst)ように最適化され、ライブなページキャッシュページを書き込み可能なscatterlistに配置しました。その結果、非特権ユーザーは、読み取り可能な任意のファイル(setuidバイナリや /etc/passwd を含む)のカーネルのページキャッシュコピーに、攻撃者が制御する4バイトを正確に書き込むことができます — ディスク上のファイルには触れずに。動作するPoCは732バイトのPythonスクリプトです。レースコンディションは発生しません。ディストリビューションごとのオフセットも不要です。Ubuntu、RHEL、Amazon Linux、SUSE で確実に動作します。
Attacker opens AF_ALG socket (family 38, type 5) └─ Binds to "authencesn(hmac(sha256),cbc(aes))" └─ Sets SOL_ALG (279) options including key and authsize └─ Accepts a connection socket
Attacker opens target file (e.g., /etc/passwd) read-only └─ Uses splice() to feed page-cache pages into the AEAD socket's RX buffer └─ Sends crafted AAD via sendmsg() — bytes 4–7 of AAD = attacker-controlled write value
authencesn performs in-place decryption: └─ scatterwalk_map_and_copy writes seqno_lo into the chained page-cache page └─ recvmsg() returns an error (HMAC fails — expected), but the write already happened
Page-cache now contains attacker-modified copy of the file └─ Kernel executes from page-cache, not disk └─ On-disk file is UNCHANGED — file integrity tools see nothing
The PoC targets `/etc/passwd`: it finds the offset of the running user's UID field and overwrites it with `0000`, then invokes `su` to obtain a root shell.
---
## Detection Limitations
> **Read this section before deploying any rules below.**
This exploit has two properties that significantly limit detection coverage:
**1. The write goes to the page cache, not the filesystem.**
Any detection tool that monitors file system events — `inotify`, `fanotify`, AIDE, Tripwire, auditd path watches — will **not** observe the modification. The on-disk file is never written. This means the `-p w` (write) flags in auditd path watches for `/usr/bin/su` or `/etc/passwd` will not catch the actual exploitation write.
**2. The mechanism uses legitimate kernel interfaces.**
`AF_ALG` sockets, `splice()`, and `authencesn` all have legitimate uses (IPsec, kernel self-tests, sendfile-style I/O). Detection must focus on the *combination* of these primitives rather than any one in isolation, and false positives should be expected on systems running IPsec or doing kernel crypto testing.
**What detection CAN catch:**
- The `socket(AF_ALG, SOCK_SEQPACKET, 0)` syscall
- The `splice()` syscall correlated with the above, especially near setuid binary access
- The PoC script itself (via YARA)
- The specific `authencesn(hmac(sha256),cbc(aes))` algorithm string in process memory or script files
**What detection CANNOT catch:**
- The actual page-cache write (in-memory, no filesystem event)
- Post-exploitation use of the modified page-cache entry (looks like a normal `su` or `passwd` call)
- Variants that avoid Python or the specific algorithm string
---
## Immediate Mitigation
Before deploying detection rules, apply this mitigation on any unpatched host:```bash
# Disable algif_aead kernel module — blocks the exploit primitive entirely
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif-aead.conf
sudo rmmod algif_aead 2>/dev/null || true
緩和策が有効であることを確認するには、公式ディテクターを使用します:```bash
python3 test_cve_2026_31431.py
> **注記:** `rmmod` コマンドは、モジュールが現在ロードされていない場合に失敗しますが、これは許容されます。`modprobe.d` 設定により、今後のロードが防止されます。この緩和策は、標準的なTLS、SSH、ファイルシステム暗号化のワークロードには影響しません — `authencesn` テンプレートを使用する拡張シーケンス番号付きIPsecにのみ影響します。これは、専用VPNゲートウェイ以外では一般的ではありません。
---
## YARAルール
`cve_2026_31431.yar` として保存
> **スキャン範囲:** このルールは、ディスク上またはメモリダンプから取得したPythonスクリプトファイルをスキャンするように設計されています。既知のPoCおよび類似の変種に一致します。syscallレベルでの悪用活動は検出しません — それにはauditd/Wazuhルールを使用してください。```yara
rule CVE_2026_31431_CopyFail_PoC_HighConfidence {
meta:
description = "High-confidence match: CVE-2026-31431 Copy Fail PoC or close variant"
author = "Detection Engineering"
reference = "https://xint.io/blog/copy-fail-linux-distributions"
cve = "CVE-2026-31431"
date = "2026-04-30"
severity = "High"
cvss = "7.8"
strings:
// Algorithm string unique to this exploit path — very high fidelity
$alg_full = "authencesn(hmac(sha256),cbc(aes))" ascii
// Specific socket call signature from PoC: AF_ALG=38, SOCK_SEQPACKET=5
$socket_call = "socket(38,5,0)" ascii
// SOL_ALG socket option (decimal 279)
$solalg = "setsockopt(279" ascii
// Hex key/iv payload written via setsockopt in PoC
$key_payload = "0800010000000010" ascii
// splice() usage in context of AEAD operations
$splice = "splice(" ascii
// Target indicators from PoC (page-cache corruption targets)
$target_passwd = "/etc/passwd" ascii
$target_su = "/usr/bin/su" ascii
// AF_ALG aead bind strings
$aead_bind = "\"aead\"" ascii
condition:
// High-confidence: unique algorithm string alone is sufficient
$alg_full
or
// Medium-confidence: socket primitive + option number
($socket_call and $solalg)
or
// Medium-confidence: splice into AEAD socket targeting a setuid path
($aead_bind and $splice and ($target_passwd or $target_su))
or
// PoC hex payload present alongside splice
($key_payload and $splice)
}
rule CVE_2026_31431_CopyFail_Mechanism {
meta:
description = "Behavioral: AF_ALG AEAD + splice combination suggestive of CVE-2026-31431 technique"
author = "Detection Engineering"
reference = "https://xint.io/blog/copy-fail-linux-distributions"
cve = "CVE-2026-31431"
date = "2026-04-30"
severity = "Medium"
note = "Higher false positive rate than HighConfidence rule — review matches in context"
strings:
$authencesn = "authencesn" ascii nocase
$af_alg_num = "socket(38" ascii
$sol_alg_num = "279" ascii
$splice = "splice(" ascii
condition:
($authencesn and $splice)
or
($af_alg_num and $sol_alg_num and $splice)
}
/etc/audit/rules.d/cve-2026-31431.rules として保存