
CVE-2026-31431 Linux 커널 LPE 취약점(Copy Fail)에 대한 탐지 규칙, YARA 시그니처, auditd/Wazuh 규칙 및 MISP 이벤트 템플릿입니다. IoC, 완화 단계 및 익스플로잇 분석을 포함합니다.
게시일: 2026-04-30
CVSSv3: 7.8 (높음)
유형: 로컬 권한 상승 (LPE)
서브시스템: Linux 커널 algif_aead / authencesn 암호화 템플릿
영향 대상: Linux 커널 4.14 – 6.18.21 (2017년 이후 사실상 모든 배포판)
참고 자료:
CVE-2026-31431은 커널 4.14(2017)에서 세 가지 독립적인 변경 사항이 교차하면서 발생한 논리적 결함입니다.
authencesn 템플릿(2011년 IPsec ESN 지원을 위해 추가됨)은 출력 버퍼 경계를 넘어 4바이트의 스크래치 데이터를 기록합니다.AF_ALG는 2015년에 AEAD 지원을 추가하여, 사용자 공간이 페이지 캐시된 파일에서 splice()를 통해 데이터를 제출할 수 있게 되었습니다.algif_aead.c가 제자리 연산(req->src == req->dst)을 위해 최적화되어, 라이브 페이지 캐시 페이지를 쓰기 가능한 scatterlist에 배치했습니다.결과: 권한이 없는 사용자가 디스크 상의 파일을 건드리지 않고도 setuid 바이너리 및 /etc/passwd를 포함한 모든 읽기 가능한 파일의 커널 페이지 캐시 복사본에 정확히 4바이트의 공격자 제어 데이터를 쓸 수 있습니다. 작동 가능한 PoC는 732바이트 Python 스크립트입니다. 경쟁 조건이 없고, 배포판별 오프셋도 필요하지 않습니다. Ubuntu, RHEL, Amazon Linux, SUSE에서 안정적으로 동작합니다.
Attacker opens AF_ALG socket (family 38, type 5) └─ Binds to "authencesn(hmac(sha256),cbc(aes))" └─ Sets SOL_ALG (279) options including key and authsize └─ Accepts a connection socket
Attacker opens target file (e.g., /etc/passwd) read-only └─ Uses splice() to feed page-cache pages into the AEAD socket's RX buffer └─ Sends crafted AAD via sendmsg() — bytes 4–7 of AAD = attacker-controlled write value
authencesn performs in-place decryption: └─ scatterwalk_map_and_copy writes seqno_lo into the chained page-cache page └─ recvmsg() returns an error (HMAC fails — expected), but the write already happened
Page-cache now contains attacker-modified copy of the file └─ Kernel executes from page-cache, not disk └─ On-disk file is UNCHANGED — file integrity tools see nothing
PoC는 `/etc/passwd`를 대상으로 합니다. 실행 중인 사용자의 UID 필드 오프셋을 찾아 `0000`으로 덮어쓰고, `su`를 호출하여 루트 셸을 획득합니다.
---
## 탐지 한계
> **아래 규칙을 배포하기 전에 이 섹션을 읽어보세요.**
이 익스플로잇은 탐지 범위를 크게 제한하는 두 가지 특성을 가지고 있습니다.
**1. 쓰기 작업은 파일 시스템이 아닌 페이지 캐시에 이루어집니다.**
파일 시스템 이벤트(`inotify`, `fanotify`, AIDE, Tripwire, auditd 경로 감시)를 모니터링하는 모든 탐지 도구는 **수정을 관찰하지 않습니다**. 디스크 상의 파일은 절대 쓰여지지 않습니다. 즉, `/usr/bin/su` 또는 `/etc/passwd`에 대한 auditd 경로 감시의 `-p w`(쓰기) 플래그는 실제 익스플로잇 쓰기를 포착하지 못합니다.
**2. 이 메커니즘은 합법적인 커널 인터페이스를 사용합니다.**
`AF_ALG` 소켓, `splice()`, `authencesn`은 모두 합법적인 용도(IPsec, 커널 자체 테스트, sendfile 스타일 I/O)가 있습니다. 탐지는 이러한 기본 요소 중 하나만이 아니라 *조합*에 초점을 맞춰야 하며, IPsec을 실행하거나 커널 암호화 테스트를 수행하는 시스템에서는 오탐이 예상됩니다.
**탐지가 가능한 것:**
- `socket(AF_ALG, SOCK_SEQPACKET, 0)` 시스템 호출
- 위와 연관된 `splice()` 시스템 호출, 특히 setuid 바이너리 접근 근처
- PoC 스크립트 자체(YARA를 통해)
- 프로세스 메모리 또는 스크립트 파일 내 특정 `authencesn(hmac(sha256),cbc(aes))` 알고리즘 문자열
**탐지가 불가능한 것:**
- 실제 페이지 캐시 쓰기(인메모리, 파일 시스템 이벤트 없음)
- 수정된 페이지 캐시 항목의 사후 익스플로잇 사용(정상적인 `su` 또는 `passwd` 호출처럼 보임)
- Python 또는 특정 알고리즘 문자열을 피하는 변형
---
## 즉시 완화 조치
탐지 규칙을 배포하기 전에 패치되지 않은 모든 호스트에 다음 완화 조치를 적용하세요.```bash
# Disable algif_aead kernel module — blocks the exploit primitive entirely
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif-aead.conf
sudo rmmod algif_aead 2>/dev/null || true
완화 조치가 활성화되었는지 확인 공식 탐지기를 사용하여:```bash
python3 test_cve_2026_31431.py
> **참고:** `rmmod` 명령어는 모듈이 현재 로드되지 않은 경우 실패합니다. 이는 허용 가능한 현상입니다. `modprobe.d` 설정이 향후 로드를 방지합니다. 이 완화 조치는 표준 TLS, SSH 또는 파일시스템 암호화 워크로드에는 영향을 미치지 않으며, `authencesn` 템플릿을 사용하는 Extended Sequence Numbers가 적용된 IPsec에만 영향을 미칩니다. 이는 전용 VPN 게이트웨이 외부에서는 드문 경우입니다.
---
## YARA 규칙
`cve_2026_31431.yar`로 저장
> **스캔 범위:** 이 규칙은 디스크 상의 Python 스크립트 파일이나 메모리 덤프에서 추출된 파일을 스캔하도록 설계되었습니다. 알려진 PoC 및 유사 변종과 일치합니다. 시스템 콜 수준에서의 익스플로잇 활동은 감지하지 않습니다. 이를 위해서는 auditd/Wazuh 규칙을 사용하십시오.```yara
rule CVE_2026_31431_CopyFail_PoC_HighConfidence {
meta:
description = "High-confidence match: CVE-2026-31431 Copy Fail PoC or close variant"
author = "Detection Engineering"
reference = "https://xint.io/blog/copy-fail-linux-distributions"
cve = "CVE-2026-31431"
date = "2026-04-30"
severity = "High"
cvss = "7.8"
strings:
// Algorithm string unique to this exploit path — very high fidelity
$alg_full = "authencesn(hmac(sha256),cbc(aes))" ascii
// Specific socket call signature from PoC: AF_ALG=38, SOCK_SEQPACKET=5
$socket_call = "socket(38,5,0)" ascii
// SOL_ALG socket option (decimal 279)
$solalg = "setsockopt(279" ascii
// Hex key/iv payload written via setsockopt in PoC
$key_payload = "0800010000000010" ascii
// splice() usage in context of AEAD operations
$splice = "splice(" ascii
// Target indicators from PoC (page-cache corruption targets)
$target_passwd = "/etc/passwd" ascii
$target_su = "/usr/bin/su" ascii
// AF_ALG aead bind strings
$aead_bind = "\"aead\"" ascii
condition:
// High-confidence: unique algorithm string alone is sufficient
$alg_full
or
// Medium-confidence: socket primitive + option number
($socket_call and $solalg)
or
// Medium-confidence: splice into AEAD socket targeting a setuid path
($aead_bind and $splice and ($target_passwd or $target_su))
or
// PoC hex payload present alongside splice
($key_payload and $splice)
}
rule CVE_2026_31431_CopyFail_Mechanism {
meta:
description = "Behavioral: AF_ALG AEAD + splice combination suggestive of CVE-2026-31431 technique"
author = "Detection Engineering"
reference = "https://xint.io/blog/copy-fail-linux-distributions"
cve = "CVE-2026-31431"
date = "2026-04-30"
severity = "Medium"
note = "Higher false positive rate than HighConfidence rule — review matches in context"
strings:
$authencesn = "authencesn" ascii nocase
$af_alg_num = "socket(38" ascii
$sol_alg_num = "279" ascii
$splice = "splice(" ascii
condition:
($authencesn and $splice)
or
($af_alg_num and $sol_alg_num and $splice)
}
/etc/audit/rules.d/cve-2026-31431.rules로 저장
다시 로드:```bash sudo augenrules --load
sudo auditctl -R /etc/audit/rules.d/cve-2026-31431.rules
번역할 Markdown 콘텐츠를 제공해 주세요.```bash
## ============================================================
## CVE-2026-31431 "Copy Fail" — Auditd Detection Rules
## ============================================================
## These rules capture the MECHANISM of the exploit (socket +
## splice syscalls) and correlated /etc/passwd access patterns.
##
## IMPORTANT: These rules will NOT detect the page-cache write
## itself — it is an in-memory operation with no filesystem
## event. File path watches (-w) on setuid binaries or
## /etc/passwd will not fire on the exploit write.
##
## Correlate rule hits across audit.key values to build signal:
## A hit on afalg_socket followed closely by a hit on
## splice_syscall from the same process is a strong indicator.
## ============================================================