¡¾¸´ÏÖ¡¿LinuxÄÚºËͨÓ÷ì϶ Copy Fail£¨CVE-2026-31431£©

°ä²¼¹¦·ò 2026-04-30

·ìϼûèÊö


Copy Fail£¨CVE-2026-31431£©ÊÇ LinuxÄÚºËauthencesn¼ÓÃÜÄ£°åÖеÄÒ»´¦Âß¼­·ì϶¡£¸Ã·ì϶ÔÊÐíµÍȨÏÞ±¾µØÓû§ £¬ÏòϵͳËÁÒâ¿É¶ÁÎļþµÄÒ³»º´æÌáÒéÈ·¶¨ÐÔ¡¢¿ÉÊܿصĠ4 ×Ö½ÚдÈë¡£¹¥»÷Õß½öÐèÒ»¶Î 732 ×ֽڵĠPython ¾ç±¾ £¬¾ÍÄܴ۸Ġsetuid ÌØÈ¨¶þ½øÔìÎļþ £¬¼´¿ÉÔÚ 2017 ÄêÖ®ºó°ä²¼µÄ¾ø´óÎÞÊý Linux ¿¯ÐаæÉÏʵÏÖ±¾µØÌáȨ £¬Ö±½Ó»ñÈ¡root ×î¸ßȨÏÞ¡£¸Ã·ì϶CVSSÆÀ·ÖΪ7.8 £¬µÈ¼¶Îª¸ßΣ¡£

ÓëDirty Cow¡¢Dirty PipeµÈ¾­µäLinux±¾µØÌáȨ·ì϶Ïà±È £¬Copy FailµÄ×î´óÓÅÊÆÔÚÓÚÎÞÐèÒÀÀµ¾ºÕùǰÌá £¬·ì϶ÀûÓóɹ¦ÂʺͲ»±äÐÔ¸ü¸ß¡£´Ë±í £¬¸Ã·ì϶¸²¸ÇµÄϵͳÁìÓò¸ü¹ã £¬ÏÕЩӰÏìËùÓÐLinux¿¯Ðаæ¡£


Ó°ÏìÁìÓò


? Linux Kernel 4.14¼°ÒÔÉϰ汾 £¬Ö±ÖÁ²¹¶¡°ä²¼Ç°µÄËùÓа汾£¨4.14 - 6.xϵÁУ©

? Ubuntu¡¢Amazon Linux¡¢RHEL¡¢SUSEµÈÖ÷Á÷¿¯Ðаæ

? ÈÝÆ÷»·¾³£¨¹Ù·½Åû¶¿ÉÄÜʵÏÖÈÝÆ÷ÌÓÒÝ£©


·ì϶µÀÀí


2017ÄêÌá½»µÄcommit 72548b093ee3Ϊalgif_aead.cÒýÈëÁËAEAD£¨´ø¹ØÁªÊý¾ÝµÄÈÏÖ¤¼ÓÃÜ£©²Ù×÷µÄԭλÓÅ»¯¡£ÔÚ½âÃÜÁ÷³ÌÖÐ £¬Äں˽«AADºÍÃÜÎÄÊý¾Ý´ÓTX SGL¿½±´ÖÁRX»º³åÇø £¬²¢Í¨¹ýsg_chain()½«±êǩҳÒÔÒýÓ÷½Ê½Á´½Ó¡£ËæºóÉèÖÃreq->src = req->dst £¬Ê¹µÃÕýÔ­À´×ÔÎļþÒ³»º´æµÄÒ³£¨¾­ÓÉsplice´«È룩½øÈëÁË¿ÉдµÄÖ¸±êÉ¢ÁÐÁÐ±í£¨Destination SGL£©¡£


ÔÚauthencesnÄ£°åµÄ½âÃܺ¯Êýcrypto_authenc_esn_decrypt()ÖÐ £¬µ±srcÓëdst±»ÊÓΪͳһԭλ»º³åÇøÊ± £¬¸Ãº¯Êý»áÏò±êÇ©ÇøÓòдÈë4¸ö×Ö½Ú¡£È»¶ø £¬´ËдÈë²Ù×÷²úÉúÔÚ±êÇ©²é³­Ö®Ç°¡ª¡ª¼´±ãºóÐøÒòÈÏÖ¤±êǩУÑéʧ°Ü·µ»Ø-EBADMSGÃýÎó £¬Îļþ»º´æÒ³ÖеÄ4¸ö×Ö½ÚÒѱ»´Û¸Ä¡£¸Ã·ì϶ÔÊÐí±¾µØµÍȨÏÞÓû§ÏòËÁÒâ¿É¶ÁÎļþµÄÒ³»º´æÖÐдÈë¿É¿ØÊý¾Ý £¬Ã¿´ÎÒªÇó¿É¸²¸Ç4¸ö×Ö½Ú £¬Í¨¹ýÂÅ´ÎÒªÇó¿É´Û¸ÄÖ»¶Á»òsetuid·¨Ê½ÄÚÈÝ £¬½ø¶øÊµÏÖ±¾µØÌáȨ»ò´úÂëÖ´ÐС£


·ì϶¸´ÏÖ


ͼƬ.png


°²È«½¨Òé


    £¨1£©Õýʽ·À»¤¹æ»®

    ½«Äں˸üÐÂÖÁÔ̺¬commit a664bf3d603d µÄ°æ±¾¡£

    https://github.com/torvalds/linux/commit/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5


    £¨2£©Ò»Ê±·À»¤´ëÊ©

    ʹÓÃseccomp×èÖ¹AF_ALGÌ×½Ó×Ö´´½¨ £¬»ò½«algif_aeadÄ£¿éÁÐÈëºÚÃûµ¥£º

    Plain Text

    echo   "install algif_aead /bin/false" >   /etc/modprobe.d/disable-algif-aead.conf

    rmmod algif_aead 2>/dev/null


    ²Î¿¼Á´½Ó£º

    [1]https://xint.io/blog/copy-fail-linux-distributions

    [2]https://copy.fail/



    ±¦ÔËÀ³¹Ù·½ÍøÕ¾»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


    ADLab³ÉÁ¢ÓÚ1999Äê £¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖÁĿǰ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö £¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑÓ×¢µçÐÅÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑÓ×¢ÒÆ¶¯Öն˰²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢5G°²È«×êÑÓ×¢AI°²È«×êÑÓ×¢ÎÀÐǰ²È«×êÑÓ×¢µÍ¿Õ°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£


    adlab.jpg