ã³ã¢ã§ã¯ Linux Copy FailãDirty FragãFragnesiaãšåæ§ã®è匱æ§ã確èªãããŸããããã®è匱æ§ã«ãããæš©éã®ãªããŠãŒã¶ãŒãããŒãžãã£ãã·ã¥å ã®ããŒã¿ãäžæžãããããšã§rootæš©éãååŸã§ããŸãããã®è匱æ§ã¯DirtyDecryptãšããã³ãŒãããŒã ã§åŒã°ããŠããŸãïŒDirtyCBCãšãåŒã°ããŸãïŒããããã¿ã€ãã®ãšã¯ã¹ããã€ããå©çšå¯èœã§ãã
ãã®ãšã¯ã¹ããã€ãã®èª¬æã«ã¯ CVE èå¥åã¯èšèŒãããŠããããç ç©¶è ãã 5 æ 9 æ¥ã«ãã®åé¡ãçºèŠããã«ãŒãã«éçºè ã«å ±åãããšããããã®çºèŠã¯æ¢ã«ä¿®æ£æžã¿ã®è匱æ§ã«é¢ããå¥ã®å ±åãšéè€ããŠãããšã®åçããã£ããšã ãèšãããŠãããä¿®æ£ããããæ¢ã«ã«ãŒãã«ã«å«ãŸããŠãããããç ç©¶è ãã¯éçºãããšã¯ã¹ããã€ããå ¬éããããšã«ããããšã¯ã¹ããã€ãã®èª¬æãã倿ãããšãããã¯èåŒ±æ§ CVE-2026-31635 ãæªçšãããã®ã§ããã®è匱æ§ã«å¯Ÿããä¿®æ£ã¯ 4 æã«ã«ãŒãã«ã«åãå ¥ãããã7.0.0 ãã©ã³ãããã³ 4 æ 18 æ¥ã«ãªãªãŒã¹ããã 6.18.23 ãªãªãŒã¹ã«å«ãŸããŠããããã®åé¡ã¯ã«ãŒãã« 6.16 以éååšããŠããã
Dirty Frag ã·ãªãŒãºã®è匱æ§ãšåæ§ã«ãUDP äžã§åäœãã AF_RXRPC ãœã±ãããã¡ããªãŒãš RPC ãããã³ã«ãå®è£ ãã RxRPC ãã©ã€ãã«æ°ããªè匱æ§ãååšããŸãããã®åé¡ã¯ãrxgk_verify_response() 颿°ã«ãããããŒã¿ãµã€ãºãã§ãã¯ã®èª€ããåå ã§ããæ¬æ¥ã¯ãif (auth_len > len)ããšãã§ãã¯ãã¹ããšãããããif (auth_len < len)ããšæå®ãããŠããããã蚱容ãµã€ãºãè¶ ããããŒã¿ã rxgk_decrypt_skb() 颿°ã«æž¡ãããŠããŸãããrxgk_decrypt_skb() ãå®è¡ããããšãäžèŠãªãããã¡ãªã³ã°ãé¿ããããã倿Žå 容ãããŒãžãã£ãã·ã¥ã«çŽæ¥æ¿å ¥ãããããŒã¿ã埩å·åãããŸããããããããµã€ãºãã§ãã¯ã誀ã£ãŠãããããããŒãžãã£ãã·ã¥å ã®æå®ããããªãã»ããã®ããŒã¿ãäžæžããããå¯èœæ§ããããŸããã
ãã®è匱æ§ãæªçšããã«ã¯ãsuid rootãã©ã°ä»ãã®ããã°ã©ã ãã¡ã€ã«ãèªã¿èŸŒã¿ïŒããŒãžãã£ãã·ã¥ãžã®é 眮ã確å®ã«ããããïŒãããŒãžãã£ãã·ã¥å ã®ããã°ã©ã ã³ãŒãã®äžéšã/usr/bin/shãèµ·åããã³ãŒãã«çœ®ãæããŸãããã®åŸãããã°ã©ã ãå®è¡ãããšããã©ã€ãäžã®å ã®å®è¡å¯èœãã¡ã€ã«ã§ã¯ãªããããŒãžãã£ãã·ã¥ãã倿Žãããã³ããŒãã¡ã¢ãªã«ããŒããããŸãããã®ãšã¯ã¹ããã€ãã¯ãã/usr/bin/suããã/bin/suããã/usr/bin/mountããã/usr/bin/passwdããã/usr/bin/chshãã®äœ¿çšããµããŒãããŠããŸãã
ãã®è匱æ§ãæªçšããã«ã¯ãã«ãŒãã«ã®ãã«ãæã« CONFIG_RXGK ãªãã·ã§ã³ãæå¹ã«ããrxrpc.ko ã«ãŒãã«ã¢ãžã¥ãŒã«ãèªåããŒãå¯èœã«ãªã£ãŠããå¿ èŠããããŸãïŒäžéšã®ã·ã¹ãã ã§ã¯ãã«ãã§ããŸããïŒããã£ã¹ããªãã¥ãŒã·ã§ã³ã«ãããè匱æ§ä¿®æ£ã®ç¶æ³ã¯ã以äžã®ããŒãžã§ç¢ºèªã§ããŸãã Debian, UbuntuSUSE/openSUSEãRHELãArchãFedoraãåé¿çãšããŠãrxrpcã«ãŒãã«ã¢ãžã¥ãŒã«ã®èªã¿èŸŒã¿ããããã¯ããããšãã§ããŸãã
sh -c "pâârintf 'install rxrpc /bin/false\n' > /etc/modprobe.d/dirtydecrypt.conf; rmmod rxrpc 2>/dev/null; true"
ããã«ãã«ãŒãã«éçºè
ã¡ãŒãªã³ã°ãªã¹ãã§ãã®å
¬éã«ã€ããŠèšåããããšãã§ããŸãã Linux ãã®ãããã¯ãæå·åAPIïŒAF_ALGïŒã«ãããŠããskcipherãããã³ãaeadãã¢ã«ãŽãªãºã ã«ããåŸ©å·æã«ããŒãžãã£ãã·ã¥ãžã®çŽæ¥ã¢ã¯ã»ã¹ã䜿çšããæé©åãå®å
šã«ç¡å¹åããŸãããããã®æé©åã¯äžèŠãªããŒã¿ãããã¡ãªã³ã°ãæé€ããŸãããæ·±å»ãªè匱æ§ãæããªã¹ã¯ããããŸããç¡å¹åããŠããå¥ã®ãããã¡ãžã®è¿œå ã®ã³ããŒæäœãçºçãããããããã©ãŒãã³ã¹ã®äœäžã¯ããããããšäºæ³ãããŸãããã®ãããã¯æå·åAPIãµãã·ã¹ãã ã®ã¡ã³ããã«æ¿èªãããå°æ¥ã®ã«ãŒãã«ãªãªãŒã¹ãžã®çµã¿èŸŒã¿ã«åããŠæ©èœãéçºãããŠãããcryptodevããã©ã³ãã«å«ãŸããŠããŸãã Linux.
åºæïŒ ãªãŒãã³ããã.ru
