Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Detections-CVE-2026-31431 — CVE-2026-31431 Linux 커널 LPE 취약점(Copy Fail)에 대한 탐지 규칙, YARA 시그니처, auditd/Wazuh 규칙 및 MISP 이벤트 템플릿입니다. IoC, 완화 단계 및 익스플로잇 분석을 포함합니다. | Kitploit
도구/GitHubGitHub/insomnisec/detections-cve-2026-31431
Indicator of Compromise (IOC) ManagementPrivilege EscalationVulnerability AnalysisExploitationForensicsThreat IntelligenceIntrusion DetectionLearning & EducationIncident Response

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHubinsomnisec/detections-cve-2026-31431

Detections-CVE-2026-31431

CVE-2026-31431 Linux 커널 LPE 취약점(Copy Fail)에 대한 탐지 규칙, YARA 시그니처, auditd/Wazuh 규칙 및 MISP 이벤트 템플릿입니다. IoC, 완화 단계 및 익스플로잇 분석을 포함합니다.

저장소 보기
2114개월 전아직 검토되지 않음

MOVING TO: https://github.com/insomnisec/public_cve_detections

장기적인 탐지 게시물 관리를 위해 이동 중입니다.

이 저장소는 2026년 6월에 제거될 예정입니다.

앞으로는 다른 저장소를 사용해 주세요.

CVE-2026-31431 "Copy Fail" — 탐지 및 대응 패키지

게시일: 2026-04-30
CVSSv3: 7.8 (높음)
유형: 로컬 권한 상승 (LPE)
서브시스템: Linux 커널 algif_aead / authencesn 암호화 템플릿
영향 대상: Linux 커널 4.14 – 6.18.21 (2017년 이후 사실상 모든 배포판)
참고 자료:

  • Xint/Theori Write-up
  • 공식 PoC
  • oss-security 공개
  • copy.fail

목차

  1. 취약점 요약
  2. 익스플로잇 작동 방식
  3. 탐지 한계
  4. 즉시 완화 조치
  5. YARA 규칙
  6. Auditd 규칙
  7. Wazuh 규칙
  8. MISP 이벤트 템플릿
  9. 패치 및 수정
  10. 주요 IoC 참조

취약점 요약

CVE-2026-31431은 커널 4.14(2017)에서 세 가지 독립적인 변경 사항이 교차하면서 발생한 논리적 결함입니다.

  1. authencesn 템플릿(2011년 IPsec ESN 지원을 위해 추가됨)은 출력 버퍼 경계를 넘어 4바이트의 스크래치 데이터를 기록합니다.
  2. AF_ALG는 2015년에 AEAD 지원을 추가하여, 사용자 공간이 페이지 캐시된 파일에서 splice()를 통해 데이터를 제출할 수 있게 되었습니다.
  3. 2017년에 algif_aead.c가 제자리 연산(req->src == req->dst)을 위해 최적화되어, 라이브 페이지 캐시 페이지를 쓰기 가능한 scatterlist에 배치했습니다.

결과: 권한이 없는 사용자가 디스크 상의 파일을 건드리지 않고도 setuid 바이너리 및 /etc/passwd를 포함한 모든 읽기 가능한 파일의 커널 페이지 캐시 복사본에 정확히 4바이트의 공격자 제어 데이터를 쓸 수 있습니다. 작동 가능한 PoC는 732바이트 Python 스크립트입니다. 경쟁 조건이 없고, 배포판별 오프셋도 필요하지 않습니다. Ubuntu, RHEL, Amazon Linux, SUSE에서 안정적으로 동작합니다.


익스플로잇 작동 방식```

Attacker opens AF_ALG socket (family 38, type 5) └─ Binds to "authencesn(hmac(sha256),cbc(aes))" └─ Sets SOL_ALG (279) options including key and authsize └─ Accepts a connection socket

Attacker opens target file (e.g., /etc/passwd) read-only └─ Uses splice() to feed page-cache pages into the AEAD socket's RX buffer └─ Sends crafted AAD via sendmsg() — bytes 4–7 of AAD = attacker-controlled write value

authencesn performs in-place decryption: └─ scatterwalk_map_and_copy writes seqno_lo into the chained page-cache page └─ recvmsg() returns an error (HMAC fails — expected), but the write already happened

Page-cache now contains attacker-modified copy of the file └─ Kernel executes from page-cache, not disk └─ On-disk file is UNCHANGED — file integrity tools see nothing

PoC는 `/etc/passwd`를 대상으로 합니다. 실행 중인 사용자의 UID 필드 오프셋을 찾아 `0000`으로 덮어쓰고, `su`를 호출하여 루트 셸을 획득합니다.

---

## 탐지 한계

> **아래 규칙을 배포하기 전에 이 섹션을 읽어보세요.**

이 익스플로잇은 탐지 범위를 크게 제한하는 두 가지 특성을 가지고 있습니다.

**1. 쓰기 작업은 파일 시스템이 아닌 페이지 캐시에 이루어집니다.**
파일 시스템 이벤트(`inotify`, `fanotify`, AIDE, Tripwire, auditd 경로 감시)를 모니터링하는 모든 탐지 도구는 **수정을 관찰하지 않습니다**. 디스크 상의 파일은 절대 쓰여지지 않습니다. 즉, `/usr/bin/su` 또는 `/etc/passwd`에 대한 auditd 경로 감시의 `-p w`(쓰기) 플래그는 실제 익스플로잇 쓰기를 포착하지 못합니다.

**2. 이 메커니즘은 합법적인 커널 인터페이스를 사용합니다.**
`AF_ALG` 소켓, `splice()`, `authencesn`은 모두 합법적인 용도(IPsec, 커널 자체 테스트, sendfile 스타일 I/O)가 있습니다. 탐지는 이러한 기본 요소 중 하나만이 아니라 *조합*에 초점을 맞춰야 하며, IPsec을 실행하거나 커널 암호화 테스트를 수행하는 시스템에서는 오탐이 예상됩니다.

**탐지가 가능한 것:**
- `socket(AF_ALG, SOCK_SEQPACKET, 0)` 시스템 호출
- 위와 연관된 `splice()` 시스템 호출, 특히 setuid 바이너리 접근 근처
- PoC 스크립트 자체(YARA를 통해)
- 프로세스 메모리 또는 스크립트 파일 내 특정 `authencesn(hmac(sha256),cbc(aes))` 알고리즘 문자열

**탐지가 불가능한 것:**
- 실제 페이지 캐시 쓰기(인메모리, 파일 시스템 이벤트 없음)
- 수정된 페이지 캐시 항목의 사후 익스플로잇 사용(정상적인 `su` 또는 `passwd` 호출처럼 보임)
- Python 또는 특정 알고리즘 문자열을 피하는 변형

---

## 즉시 완화 조치

탐지 규칙을 배포하기 전에 패치되지 않은 모든 호스트에 다음 완화 조치를 적용하세요.```bash
# Disable algif_aead kernel module — blocks the exploit primitive entirely
echo "install algif_aead /bin/false" | sudo tee /etc/modprobe.d/disable-algif-aead.conf
sudo rmmod algif_aead 2>/dev/null || true

완화 조치가 활성화되었는지 확인 공식 탐지기를 사용하여:```bash

Exit 0 = not vulnerable / mitigated

Exit 2 = VULNERABLE

python3 test_cve_2026_31431.py

> **참고:** `rmmod` 명령어는 모듈이 현재 로드되지 않은 경우 실패합니다. 이는 허용 가능한 현상입니다. `modprobe.d` 설정이 향후 로드를 방지합니다. 이 완화 조치는 표준 TLS, SSH 또는 파일시스템 암호화 워크로드에는 영향을 미치지 않으며, `authencesn` 템플릿을 사용하는 Extended Sequence Numbers가 적용된 IPsec에만 영향을 미칩니다. 이는 전용 VPN 게이트웨이 외부에서는 드문 경우입니다.

---

## YARA 규칙

`cve_2026_31431.yar`로 저장

> **스캔 범위:** 이 규칙은 디스크 상의 Python 스크립트 파일이나 메모리 덤프에서 추출된 파일을 스캔하도록 설계되었습니다. 알려진 PoC 및 유사 변종과 일치합니다. 시스템 콜 수준에서의 익스플로잇 활동은 감지하지 않습니다. 이를 위해서는 auditd/Wazuh 규칙을 사용하십시오.```yara
rule CVE_2026_31431_CopyFail_PoC_HighConfidence {
    meta:
        description     = "High-confidence match: CVE-2026-31431 Copy Fail PoC or close variant"
        author          = "Detection Engineering"
        reference       = "https://xint.io/blog/copy-fail-linux-distributions"
        cve             = "CVE-2026-31431"
        date            = "2026-04-30"
        severity        = "High"
        cvss            = "7.8"

    strings:
        // Algorithm string unique to this exploit path — very high fidelity
        $alg_full      = "authencesn(hmac(sha256),cbc(aes))" ascii

        // Specific socket call signature from PoC: AF_ALG=38, SOCK_SEQPACKET=5
        $socket_call   = "socket(38,5,0)" ascii

        // SOL_ALG socket option (decimal 279)
        $solalg        = "setsockopt(279" ascii

        // Hex key/iv payload written via setsockopt in PoC
        $key_payload   = "0800010000000010" ascii

        // splice() usage in context of AEAD operations
        $splice        = "splice(" ascii

        // Target indicators from PoC (page-cache corruption targets)
        $target_passwd = "/etc/passwd" ascii
        $target_su     = "/usr/bin/su" ascii

        // AF_ALG aead bind strings
        $aead_bind     = "\"aead\"" ascii

    condition:
        // High-confidence: unique algorithm string alone is sufficient
        $alg_full
        or
        // Medium-confidence: socket primitive + option number
        ($socket_call and $solalg)
        or
        // Medium-confidence: splice into AEAD socket targeting a setuid path
        ($aead_bind and $splice and ($target_passwd or $target_su))
        or
        // PoC hex payload present alongside splice
        ($key_payload and $splice)
}

rule CVE_2026_31431_CopyFail_Mechanism {
    meta:
        description     = "Behavioral: AF_ALG AEAD + splice combination suggestive of CVE-2026-31431 technique"
        author          = "Detection Engineering"
        reference       = "https://xint.io/blog/copy-fail-linux-distributions"
        cve             = "CVE-2026-31431"
        date            = "2026-04-30"
        severity        = "Medium"
        note            = "Higher false positive rate than HighConfidence rule — review matches in context"

    strings:
        $authencesn    = "authencesn" ascii nocase
        $af_alg_num    = "socket(38" ascii
        $sol_alg_num   = "279" ascii
        $splice        = "splice(" ascii

    condition:
        ($authencesn and $splice)
        or
        ($af_alg_num and $sol_alg_num and $splice)
}

Auditd 규칙

/etc/audit/rules.d/cve-2026-31431.rules로 저장

다시 로드:```bash sudo augenrules --load

or on older systems:

sudo auditctl -R /etc/audit/rules.d/cve-2026-31431.rules

번역할 Markdown 콘텐츠를 제공해 주세요.```bash
## ============================================================
## CVE-2026-31431 "Copy Fail" — Auditd Detection Rules
## ============================================================
## These rules capture the MECHANISM of the exploit (socket +
## splice syscalls) and correlated /etc/passwd access patterns.
##
## IMPORTANT: These rules will NOT detect the page-cache write
## itself — it is an in-memory operation with no filesystem
## event. File path watches (-w) on setuid binaries or
## /etc/passwd will not fire on the exploit write.
##
## Correlate rule hits across audit.key values to build signal:
## A hit on afalg_socket followed closely by a hit on
## splice_syscall from the same process is a strong indicator.
## ============================================================
도구 다운로드