
- TOP
- ã¿ã°äžèЧ
- åå¿è
åå¿è
ã€ãã³ã
ãã¬ãžã³
æè¡ããã°
æ¬èšäºã§ã¯ãITæªçµéšãã転è·ããç§ãDockerãç¥ããçè§£ãããŸã§ã®ã¹ãããã解説ããŸãã
Linuxã¯ãå€ãã®äŒæ¥ã·ã¹ãã ãã¯ã©ãŠãç°å¢ãã³ã³ããåºç€ã§äœ¿ãããŠããŸãã ãã®ãããLinuxã«ãŒãã«ã«æ·±å»ãªè匱æ§ãèŠã€ãããšã圱é¿ã¯ãšãŠã倧ãããªããŸãã Elastic Security Labs ã¯ãLinuxã«ãŒãã«ã®æš©éææ Œè匱æ§ã§ãã Copy Fail (CVE-2026-31431) ãCopy Fail 2ããã㊠DirtyFrag ãåæããŸããããããã¯ãLinuxã® page cache ã«é¢ä¿ãããã°ãæªçšããéåžžãŠãŒã¶ãŒãã rootæš©é ãååŸã§ããå¯èœæ§ãããæ»æã§ãã ç¹ã« Copy Fail (CVE-2026-31431) ã¯å®éã®æ»æã§æªçšãããããšãå ±åãããŠãããç±³åœCISAã® Known Exploited Vulnerabilities (KEV) ã«ã¿ãã° ã«ã远å ãããŠããŸããKEVã«ã¿ãã°ã«èŒããšããããšã¯ããæºäžã®è匱æ§ãã§ã¯ãªããçŸå®ã«æ»æã§äœ¿ãããŠããè匱æ§ãã§ããããšãæå³ããŸããç±³åœã®é£éŠæ©é¢ã¯æéå
ã®ãããé©çšã矩åä»ããããã¬ãã«ã§ãããæ°éäŒæ¥ã«ãšã£ãŠãåªå
察å¿ãã¹ã匷ãã·ã°ãã«ã§ãã ãã®èšäºã§ã¯ããã®æ»æãã»ãã¥ãªãã£åå¿è
ã«ããããããã«æŽçããªãããElastic Securityãã©ã®ããã«è
åšãåæããæ€ç¥ã«ã€ãªããŠããã®ãããã㊠Elasticãå
¬éããŠããæ€ç¥ã«ãŒã« ã玹ä»ããŸãã ç®æ¬¡ ãŸããäœãå±éºãªã®ãïŒ page cache ãšã¯äœãïŒ page cache corruption ãšã¯ïŒ Copy Fail ã¯äœãããã®ãïŒ DirtyFrag ã¯äœãéãã®ãïŒ â ïž ãããæéèŠïŒCopy Fail ã®ãããã ãã§ã¯äžåå ãªã Elastic ã®åæãéèŠãªã®ãïŒ Elastic ãå
¬éããæ€ç¥ã«ãŒã«5æ¬ 1. Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket 2. Suspicious SUID Binary Execution 3. Suspicious Kernel Feature Activity 4. Namespace Manipulation Using Unshare 5. Privilege Escalation via SUID/SGID 5æ¬ã®ã«ãŒã«ãã©ã飿ºããã Elastic ã®åŒ·ã¿ïŒãã¹ãŠã®æ€ç¥ã«ãŒã«ã GitHub ã§å
¬éãããŠãã ããããªãéèŠãªã®ãïŒ æ¥æ¬ã®ãŠãŒã¶ãŒã«ãšã£ãŠã®æå³ ããžãã¹èŠç¹ã§ãªãéèŠãªã®ãïŒ ãŸãšãïŒElastic Security ã¯ãæ»æã®åœ¢ãã§ã¯ãªããæ»æã®åãããèŠã åèãªã³ã¯ ãŸããäœãå±éºãªã®ãïŒ ä»åã®ãã€ã³ãã¯ãæ»æè
ãLinuxäžã§ rootæš©é ãååŸã§ããå¯èœæ§ãããããšã§ãã rootãšã¯ãLinuxã«ãããæãåŒ·ãæš©éãæã€ãŠãŒã¶ãŒã§ãã ããšãããªãããã«å
šäœã®ãã¹ã¿ãŒããŒãæã€ç®¡çè
ã®ãããªååšã§ãã éåžžãŠãŒã¶ãŒã¯ãèªåã®éšå±ãèš±å¯ãããå Žæã«ããå
¥ããŸããã ãããrootã¯ãã·ã¹ãã å
šäœã®èšå®å€æŽããã¡ã€ã«ã®èªã¿æžããããã»ã¹ã®åæ¢ããŠãŒã¶ãŒäœæãªã©ãå€ãã®æäœãã§ããŸãã ã€ãŸããæ»æè
ãrootæš©éãåããšã次ã®ãããªããšãå¯èœã«ãªããŸãã æ©å¯ãã¡ã€ã«ãèªã ã»ãã¥ãªãã£ããŒã«ãæ¢ãã ãã«ãŠã§ã¢ãèšçœ®ãã ãã°ãæ¹ãããã ä»ã®ã·ã¹ãã ãžäŸµå
¥ããè¶³ããããäœã ããã¯ãåãªãã1å°ã®LinuxãµãŒããŒã®åé¡ãã§ã¯ãããŸããã äŒæ¥ã®ã¯ã©ãŠãç°å¢ãã³ã³ããåºç€ãæ¥åã·ã¹ãã å
šäœã«åœ±é¿ããå¯èœæ§ããããŸãã page cache ãšã¯äœãïŒ ä»åã®æ»æãçè§£ããããã«ããŸã page cache ãçè§£ããå¿
èŠããããŸãã page cacheãšã¯ãLinuxããã¡ã€ã«ã¢ã¯ã»ã¹ãéãããããã«äœ¿ãã¡ã¢ãªäžã®äžæçãªä¿ç®¡å Žæã§ãã ããšãã°ã峿žé€šãã€ã¡ãŒãžããŠãã ããã æ¬æ£ã«ããæ¬ãããã£ã¹ã¯äžã®ãã¡ã€ã«ãã ãšããŸãã ã§ããããèªãŸããæ¬ãæ¯åæ¬æ£ãŸã§åãã«è¡ãã®ã¯é¢åã§ãã ããã§å³æžé€šå¡ã¯ãããäœ¿ãæ¬ã®ã³ããŒãæºã®äžã«çœ®ããŠãããŸãã ãã®ãæºã®äžã®ã³ããŒãããLinuxã§ãã page cache ã§ãã ããšã Linux æ¬æ£ã®æ¬ ãã£ã¹ã¯äžã®ãã¡ã€ã« æºã®äžã®ã³ã㌠page cache 峿žé€šå¡ Linuxã«ãŒãã« æ¬ãèªã人 ã¢ããªã±ãŒã·ã§ã³ éåžžãpage cacheã¯äŸ¿å©ãªä»çµã¿ã§ãã ãã¡ã€ã«ãæ¯åãã£ã¹ã¯ããèªããããã¡ã¢ãªããèªãã æ¹ãéãããã§ãã ããããä»åã®ãããªè匱æ§ã§ã¯ããã®ãã¡ã¢ãªäžã®ã³ããŒããæªçšãããŸãã page cache corruption ãšã¯ïŒ page cache corruption ãšã¯ãç°¡åã«èšããšãLinuxãä¿¡é ŒããŠããã¡ã¢ãªäžã®ãã¡ã€ã«ã³ããŒãäžæ£ã«æžãæããããšã§ãã éèŠãªã®ã¯ãæ»æè
ãå¿
ããããã£ã¹ã¯äžã®æ¬ç©ã®ãã¡ã€ã«ãæžãæããããã§ã¯ãªãããšããç¹ã§ãã æ¬ç©ã®ãã¡ã€ã«ã¯å€ãã£ãŠããªãããã«èŠããŸãã ããããLinuxãå®éã«äœ¿ãã¡ã¢ãªäžã®ã³ããŒã ããå£ãããŠããå¯èœæ§ããããŸãã ããã¯éåžžã«åä»ã§ãã ãªããªãããã¡ã€ã«ã®æ¹ãããã§ãã¯ãããŠãããã£ã¹ã¯äžã®ãã¡ã€ã«ã¯æ£åžžã«èŠããããšãããããã§ãã äžæ¹ã§ãã·ã¹ãã ã¯å£ãããpage cacheã®å
容ã䜿ã£ãŠããŸãå¯èœæ§ããããŸãã ããšãããªããäŒç€Ÿã®æ£åŒãªå¥çŽæžã¯é庫ã®äžã§ç¡äºãªã®ã«ãæ
åœè
ãæºã®äžã«çœ®ããŠããã³ããŒã ãããã£ããæžãæããããŠããç¶æ
ã§ãã æ
åœè
ããã®ã³ããŒãä¿¡ããŠåŠçãé²ãããšãééã£ã倿ã«ã€ãªãããŸãã Copy Fail ã¯äœãããã®ãïŒ Elasticã®èª¬æã«ãããšãCopy Fail 㯠Linuxã«ãŒãã«ã®æå·åŠçïŒauthencesn ãã³ãã¬ãŒãïŒã«é¢ä¿ããããžãã¯ãã°ã§ããAF_ALG ãš splice() ãšãã Linux ã®æ£èŠæ©èœãçµã¿åãããããšã§ãèªã¿åãå¯èœãªãã¡ã€ã«ã®page cacheã«å¯ŸããŠãå¶åŸ¡ããã4ãã€ãã®æžã蟌ã¿ãè¡ãããšèª¬æãããŠããŸãã ããã§éèŠãªã®ã¯ãããã setuidãã€ã㪠ã«å¯ŸããŠäœ¿ããããšããç¹ã§ãã setuid ãã€ããªãšã¯ å®è¡ãããŠãŒã¶ãŒã§ã¯ãªãããã¡ã€ã«ã®ææè
ã®æš©éã§åãç¹æ®ãªããã°ã©ã ã§ãã ããšãã° /usr/bin/su ã¯ææè
ãrootã§ãsetuid ãèšå®ãããŠãããããèªèšŒåŠçãªã©ã®äžéšã®åŠçãrootæš©éã§å®è¡ã§ããŸãããã¡ãããéåžžã¯ãã¹ã¯ãŒã確èªãªã©ã®èªèšŒãããããã誰ã§ãèªç±ã«rootã«ãªããããã§ã¯ãããŸããã ãããããã®ãrootæš©éã§åãéšåããããæ»æè
ã®æšçã«ãªããŸããCopy Fail ã®ãããªæ»æã§ã¯ããã£ã¹ã¯äžã®ãã¡ã€ã«ãçŽæ¥æžãæããã®ã§ã¯ãªããpage cacheäžã®ãã€ããªå
容ãå£ãããšã§ãrootæš©éã§å®è¡ãããåŠçãæªçšããããšããŸãã å®éã« Copy Fail ã§ã¯ã/usr/bin/su ã®ãããªsetuidãã€ããªã®ã¡ã¢ãªäžã®èŠãæ¹ãå£ãã ãã£ã¹ã¯äžã®ãã¡ã€ã«ã倿Žããã«æš©éææ Œ ã«ã€ãªããããšãã§ããŸããå
¬éãããŠããæ»æã³ãŒãã¯ãããã732ãã€ãã®Pythonã¹ã¯ãªããã§ãUbuntuãAmazon LinuxãRHELãSUSE ãšãã£ãäž»èŠãã£ã¹ããªãã¥ãŒã·ã§ã³ã§åäœããŸãã ããã§éèŠãªã®ã¯ãæ»æè
ããæªãããã«ãŠã§ã¢ãã ãã䜿ã£ãŠããããã§ã¯ãªãããšã§ãã AF_ALG ã splice() ããLinuxã«ååšããæ£èŠã®ä»çµã¿ã§ãã ã€ãŸãæ»æã¯ãå®å
šã«å€éšããèŠãŠæããã«æªããåäœã ãã§æãç«ã£ãŠããããã§ã¯ãããŸããã æ£èŠã®Linuxæ©èœãçµã¿åãããŠãã«ãŒãã«ã®çްãããã°ãçªããŠããŸãã ããããæ€ç¥ãé£ããããŸãã DirtyFrag ã¯äœãéãã®ãïŒ DirtyFragããpage cache corruption ãæªçšãã Linuxã«ãŒãã«ã®æš©éææ Œæ»æã§ãã åºæ¬ã®èãæ¹ã¯ Copy Fail ãšäŒŒãŠããŸããã æ»æçµè·¯ããããã¯ãŒã¯ã¹ã¿ãã¯ã«åºãã£ãŠãã ç¹ã倧ããç°ãªããŸãã Elasticã®ããã°ã«ãããšãDirtyFragã«ã¯2ã€ã®çµè·¯ããããŸãã çµè·¯ 䜿ãããä»çµã¿ æ»æå¯Ÿè±¡ çµæ ESPãã¹ AF_NETLINK çµç±ã®XFRM SA /usr/bin/su suãæå°éã®root shell ELFã§äžæžã RxRPCãã¹ïŒãã©ãŒã«ããã¯ïŒ AF_RXRPC + pcbc(fcrypt) /etc/passwd rootã®ãã¹ã¯ãŒããã£ãŒã«ããã¯ãªã¢ /etc/passwd ã®rootãã¹ã¯ãŒããã£ãŒã«ããã¯ãªã¢ããããšãç°å¢ã«ãã£ãŠã¯ãã¹ã¯ãŒããªãã§rootãšããŠèªèšŒãéã£ãŠããŸãå¯èœæ§ããããŸãã å®éã®æåã¯ãPAM ã SSH ã®èšå®ãshadow ãã¡ã€ã«ã®éçšç¶æ³ã«ãã£ãŠå€ãããŸãããããããããã«ããŠããrootèªèšŒã®åæãå£ãéå€§ãªæ¹ããã§ããããšã«å€ããã¯ãããŸããã ããã«ãäž¡æ¹ã®çµè·¯ãšãã« unshare(CLONE_NEWUSER | CLONE_NEWNET) ã䜿ã£ãŠ namespace capability ãååŸããåæ®µãå¿
èŠã§ããããã¯ãåŸè¿°ããæ€ç¥ããžãã¯ã§éèŠãªãã€ã³ãã«ãªããŸãã â ïž ãããæéèŠïŒCopy Fail ã®ãããã ãã§ã¯äžåå Elasticã®ããã°ãèŠåããŠããæãéèŠãªãã€ã³ãã¯æ¬¡ã®ããšã§ãã DirtyFrag 㯠algif_aead ã¢ãžã¥ãŒã«ã«äŸåããŸããã ã€ãŸããCopy Fail ã®ç·©åçïŒalgif_aead ãç¡å¹åããïŒã ããé©çšããã·ã¹ãã ã¯ãäŸç¶ãšããŠDirtyFragã«è匱ãªãŸãŸã§ãã ãCopy Fail察çã¯ãã£ãããå®å¿ããšããæã蟌ã¿ããæãå±éºãªç¶æ
ãçã¿ãŸãã äž¡æ¹ã®è匱æ§ã«å¯ŸããŠã ããããç¬ç«ãã察çãå¿
èŠ ã§ãã ãªã Elastic ã®åæãéèŠãªã®ãïŒ ããããããElastic Securityãçè§£ããããã§å€§äºãªãã€ã³ãã§ãã Elasticã¯ãåã«ãç¹å®ã®æ»æã³ãŒããèŠã€ããŸãããããšããèŠæ¹ã ããããŠããŸããã ã»ãã¥ãªãã£ç ç©¶è
ã¯ãæ°ããè匱æ§ãèŠã€ãããšããã°ãã° PoCïŒProof of ConceptïŒ ãšåŒã°ããå®èšŒã³ãŒããå
¬éããŸããããã¯ããã®æ»æãæ¬åœã«å¯èœã§ããããšã瀺ããã¢ã³ãŒããã§ãããé²åŸ¡åŽãè匱æ§ãçè§£ãã察çãæ€èšŒããããã«äœ¿ãããŸãã ããããæ»æè
ã¯ãã®å®èšŒã³ãŒãããã®ãŸãŸã®åœ¢ã§äœ¿ããšã¯éããŸããã Pythonã§æžãããã³ãŒãããGoãRustãCã«æžãæããããšãã§ããŸãã ãã¡ã€ã«åãããã»ã¹åãå€ããããšãã§ããŸããå®è¡æ¹æ³ãå°ãå€ããããšãã§ããŸãã å®éãCopy Fail ã¯ãã§ã« Python / Go / Rust / C / Metasploit ãªã©ãè€æ°ã®èšèªã»ãã¬ãŒã ã¯ãŒã¯ã§å®è£
ãå
¬éãããŠãããDirtyFrag ã Cèšèªçã®å®è£
ãå
¬éãããŠããŸãã ãã®ããã ç¹å®ã®æ»æã³ãŒãã®èŠãç®ã ããæ€ç¥ããŠãããšãå°ãå€ããããã ãã§èŠéãå¯èœæ§ããããŸã ã ElasticãéèŠããŠããã®ã¯ãæ»æã® primitive ãš behavior ã§ãã primitive ãšã¯ãæ»æãæ§æããå°ããªæè¡çãªéšåã®ããšã§ãã ããšãã°ããã«ãžã®äŸµå
¥ã§èãããšãæ»æå
šäœã¯ãäžæ£äŸµå
¥ãã§ãã ãã®äžã®primitiveã¯ã次ã®ãããªå°ããªè¡åã§ãã éµãããéãã ç£èŠã«ã¡ã©ãé¿ãã è£å£ã䜿ã 管ç宀ã«å
¥ã Linuxæ»æã§èšãã°ãprimitiveã¯æ¬¡ã®ãããªãã®ã§ãã AF_ALG ã䜿ã splice() ã䜿ã page cache ãå£ã setuidãã€ããªãæªçšãã unshare() ã§namespaceãäœã Elasticã¯ãæ»æã³ãŒããã®ãã®ã ãã§ãªããããããæ»æã®éšåãè¡åãã¿ãŒã³ãèŠãããšããŠããŸãã ããã¯ãçŸä»£ã®ã»ãã¥ãªãã£æ€ç¥ã«ãããŠéåžžã«éèŠã§ãã Elastic ãå
¬éããæ€ç¥ã«ãŒã«5æ¬ ä»å Elastic Security Labs ã¯ãCopy Fail / DirtyFrag ã«å¯Ÿå¿ããæ€ç¥ã«ãŒã«ãå
¬éããŸããã ããã§éèŠãªã®ã¯ã ãããã®ã«ãŒã«ã¯ãã¹ãŠ GitHub ã§èª°ã§ãèŠããã ãšããããšã§ãïŒåŸè¿°ïŒã 以äžã5æ¬ã®ã«ãŒã«ããããããäœãæ€ç¥ãããããç°¡æœã«ç޹ä»ããŸãã 1. Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket äœãæ€ç¥ããã: érootãŠãŒã¶ãŒã AF_ALG ãœã±ããïŒæå·åŠççšã®ç¹æ®ãªãœã±ããïŒãš splice() ãçµã¿åãããŠäœ¿ãããã®åŸ root æš©éã®ããã»ã¹å®è¡ãã·ã§ã«èµ·åã«ã€ãªããæµãã æ»æã®ã©ãã§å¹ãã: Copy Fail ã®æãæ žå¿çãªããªããã£ããçŽæ¥æããŸãã åææ¡ä»¶: ãã®ã«ãŒã«ãæå¹ã«æŽ»çšããã«ã¯ãLinux äžã§ auditd ç³»ã®ãã°ã Elastic ã«åã蟌ãã§ããå¿
èŠããããŸããå
·äœçã«ã¯ãElastic Agent ã® Auditd Manager integration ã Auditbeat ã®èšå®ãå¿
èŠã§ãããããããªãç°å¢ã§ã¯ãsocket ã splice ã®ãããªäœã¬ãã«ãª syscall ã®åãã¯èŠããŸããã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 2. Suspicious SUID Binary Execution äœãæ€ç¥ããã: suãsudoãpkexecãpasswd ãªã©ã®SUIDãã€ããªããäžå¯©ãªèŠªããã»ã¹ïŒPythonãRubyãªã©ã®ã¹ã¯ãªããã©ã³ã¿ã€ã ã/tmp ã /dev/shm ãšãã£ããŠãŒã¶ãŒæžã蟌ã¿å¯èœãã¹ããã®å®è¡ïŒãããæå°éã®åŒæ°ã§åŒã³åºããããã¿ãŒã³ã æ»æã®ã©ãã§å¹ãã: Copy Fail / DirtyFrag ã®äž¡æ¹ã® æçµæ®µé ïŒrootæš©éååŸã®ç¬éïŒãæããŸããauditd ãå
¥ã£ãŠããªãç°å¢ã§ããããã»ã¹å®è¡ã€ãã³ãã ãã§åäœãããããé©çšç¯å²ãåºãã®ãç¹åŸŽã§ãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 3. Suspicious Kernel Feature Activity äœãæ€ç¥ããã: sysctl ãªã©ã«ããã«ãŒãã«æ©èœã®äžå¯©ãªæäœãæ»æè
ãé²åŸ¡æ©æ§ãç¡å¹åããããã«ãŒãã«åäœã倿ŽãããããåããæããŸãã äœçœ®ã¥ã: ãã®ã«ãŒã«ã¯ Copy Fail / DirtyFrag å°çšãšãããããæ»æè
ãã«ãŒãã«æ©èœãäžå¯©ã«æäœããåããåºãèŠãããã®è£å©çãªæ€ç¥ã§ããä»åã®ãããªã«ãŒãã«æªçšã®æèã§ããé¢é£ããäžå¯©ãªæäœãèŠã€ããããã®è¿œå ã¬ã€ã€ãŒãšããŠåœ¹ç«ã¡ãŸãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 4. Namespace Manipulation Using Unshare äœãæ€ç¥ããã: unshare ã³ãã³ãã syscall ã«ãããŠãŒã¶ãŒããŒã ã¹ããŒã¹ïŒç¹ã« CLONE_NEWUSER | CLONE_NEWNETïŒã®äœæãšããã®çŽåŸã® root ããã»ã¹å®è¡ã»setuid(0) ã®çžé¢ã æ»æã®ã©ãã§å¹ãã: DirtyFrag åºæã®å段 ãæããŸããDirtyFrag 㯠namespace ã®ååŸãå¿
é ãªã®ã§ããããæœ°ããšæ»æãã§ãŒã³å
šäœãæç«ããªããªããŸãã åææ¡ä»¶: ãã®ã«ãŒã«ããsyscall ã¬ãã«ã®æ€ç¥éšå㯠auditd ç³»ã®ãã°ãå¿
èŠã§ããããã»ã¹å®è¡ã€ãã³ãã®éšå㯠Elastic Agent / Endpoint ã§ååŸã§ããŸãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 5. Privilege Escalation via SUID/SGID äœãæ€ç¥ããã: SUID/SGIDãã€ããªãæªçšããæš©éææ Œå
šè¬ã®ãã¿ãŒã³ãCopy Fail / DirtyFrag ã«éãããé¡äŒŒã®æš©éææ Œææ³ãåºãã«ããŒããŸãã æ»æã®ã©ãã§å¹ãã: æ±çšçãªæš©éææ Œã®æçµæ®µéãCopy Fail / DirtyFrag ã®æŽŸçãããŸã å
¬éãããŠããªãé¡äŒŒææ³ã«ãåããä¿éºçãªã«ãŒã«ã§ãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 5æ¬ã®ã«ãŒã«ãã©ã飿ºããã ãããã®ã«ãŒã«ã¯ãããããç¬ç«ããŠåããŸããã æ»æã®ç°ãªã段éãå€å±€çã«ã«ããŒããèšèš ã«ãªã£ãŠããŸãã æ»æè
ã1ã€ã®æ®µéãåé¿ããŠããå¥ã®æ®µéã§æ€ç¥ã§ãã å€å±€é²åŸ¡ïŒdefense in depthïŒ ã®èãæ¹ã§ãã Elastic ã®åŒ·ã¿ïŒãã¹ãŠã®æ€ç¥ã«ãŒã«ã GitHub ã§å
¬éãããŠãã ããã§ãElastic Security ã®éèŠãªç¹åŸŽããäŒãããŸãã Elastic ã¯ãåçšè£œåã®æ€ç¥ã«ãŒã«ããã¹ãŠ GitHub ã§å
¬éããŠããŸãã ãªããžããªã¯ãã¡ãã§ãïŒ ð elastic/detection-rules ãã®ãªããžããªã«ã¯ãElastic Security ã§äœ¿ãããæ€ç¥ã«ãŒã«ã TOML 圢åŒã§æ ŒçŽãããŠããã 誰ã§ãèªç±ã«é²èЧã»Forkã»ã³ã¡ã³ãã»Pull Request å¯èœ ã§ãã ããããªãéèŠãªã®ãïŒ ã»ãã¥ãªãã£éçšã«ãããŠãæ€ç¥ã«ãŒã«ã®äžèº«ãããããªãããšã¯ãããã€ãã®åé¡ãåŒãèµ·ãããŸãã æ€ç¥ã«ãŒã«ãèŠãããªãå Žå æ€ç¥ã«ãŒã«ãå
¬éãããŠããå Žå ã¢ã©ãŒããåºããããªãçºç«ãããããããªã ã«ãŒã«ã®ããžãã¯ãèªãã§çç±ãçè§£ã§ãã 誀æ€ç¥ãåºãŠãããã¥ãŒãã³ã°ã§ããªã æ¡ä»¶ãèªãã§ãèªç€Ÿç°å¢åãã«äŸå€ã远å ã§ãã ããã³ããŒãä¿¡ãããããªããç¶æ
èªåã§ã¬ãã¥ãŒããŠçŽåŸã§ãã æ€ç¥æŒãããã£ãŠããåå ãããããªã ããžãã¯ã®ç©ŽãçºèŠããæ¹åææ¡ã§ãã ã³ãã¥ããã£ç¥èŠãå
±æãããªã OSSãšããŠã³ãã¥ããã£ã«éå
ã§ãã ãªããæ€ç¥ã«ãŒã«ãå
¬éããŠãããã³ããŒã¯ Elastic ã ãã§ã¯ãããŸãããMicrosoft Sentinel ã Analytics rules ã GitHub ã§å
¬éããŠãããéææ§ã®é«ãã¢ãããŒããåã£ãŠããŸããäžæ¹ãå€ãã®åçš EDR/SIEM 補åã§ã¯æ€ç¥ããžãã¯ãéå
¬éã§ããŠãŒã¶ãŒãã«ãŒã«ã®äžèº«ã確èªã§ããªãããšãçãããããŸãããElastic ã¯æ©ã段éãããã®å
¬éæ¹éãäžè²«ããŠç¶ããŠããç¹ãç¹åŸŽã§ãã æ¥æ¬ã®ãŠãŒã¶ãŒã«ãšã£ãŠã®æå³ æ¥æ¬ã§ã¯ãElastic ãå®å
šã«çè§£ããŠãããšã³ãžãã¢ã¯ãŸã å€ããããŸããã ã ããããã ã«ãŒã«ããªãŒãã³ãœãŒã¹ãšããŠå
¬éãããŠãã ããšã®äŸ¡å€ã¯å€§ããã§ãã è±èªã®ããã°ãå®å
šã«çè§£ã§ããªããŠãã TOMLãã¡ã€ã«ãèªãã°æ€ç¥ããžãã¯ãããã 瀟å
SOCã®ãã¬ããžãšã㊠ã«ãŒã«ãåçµã»æ¹é ããŠåŠã¹ã èªç€Ÿç°å¢ç¹æã®èª€æ€ç¥ã«å¯Ÿã㊠èªåã§äŸå€æ¡ä»¶ã远å ã§ãã æ¥æ¬èªã³ãã¥ããã£ã§ ã«ãŒã«ã®è§£éãè°è«ã§ãã ããžãã¹èŠç¹ã§ãªãéèŠãªã®ãïŒ ãã®è©±ã¯ãã»ãã¥ãªãã£ç ç©¶è
ã ãã®ãã®ã§ã¯ãããŸããã äŒæ¥ã«ãšã£ãŠéèŠãªã®ã¯ã次ã®3ã€ã§ãã 1ã€ç®ã¯ãè¢«å®³ã®æ©æçºèŠã§ãã rootæš©éãåããããšãæ»æè
ã¯ããæ·±ãã·ã¹ãã ã«å
¥ã蟌ããŸããæ©ãæ°ã¥ããã°ã被害ãå°ããã§ããŸãã 2ã€ç®ã¯ãèª¿æ»æéã®ççž®ã§ãã SOCãã»ãã¥ãªãã£æ
åœè
ã¯ãæ¯æ¥å€ãã®ã¢ã©ãŒããèŠãŠããŸããElastic Securityã®ããã«ãæ»æã®æµããèŠããããä»çµã¿ããããšããããã¯äœãèµ·ããŠããã®ãããæ©ãçè§£ã§ããŸãã 3ã€ç®ã¯ãæªç¥ã»å€çš®ãžã®å¯Ÿå¿åã§ãã æ»æè
ã¯æ»æã³ãŒããæžãæããŸããããŒã«åãå€ããŸããå®è¡æ¹æ³ãå€ããŸãã ããããæ»æã«å¿
èŠãªåºæ¬è¡åã¯å€§ããå€ããã«ããã§ãã ã ãããããElasticãéèŠããŠããããµããŸãæ€ç¥ãã¯ãããžãã¹ã«ãšã£ãŠã䟡å€ããããŸãã ãŸãšãïŒElastic Security ã¯ãæ»æã®åœ¢ãã§ã¯ãªããæ»æã®åãããèŠã Copy Fail ã DirtyFrag ã¯ãLinuxã«ãŒãã«ã®çްãããã°ãæªçšããé«åºŠãªæ»æã§ãã ããããåå¿è
åãã«äžèšã§ãŸãšãããªããããèšããŸãã Linuxãé«éåã®ããã«äœ¿ã£ãŠãã page cache ãæªçšããã¡ã¢ãªäžã®ãã¡ã€ã«å
容ãå£ãããšã§ãéåžžãŠãŒã¶ãŒãã rootæš©éãåãæ»æã§ãã ãããŠãElastic Security Labs ã®éèŠãªè²¢ç®ã¯ããããåãªãèåŒ±æ§æ
å ±ãšããŠç޹ä»ããã ãã§ãªãã å®éã®æ€ç¥ã«ãŒã«ã«èœãšã蟌ã¿ãGitHub ã§å
¬éããŠãã ç¹ã§ãã ç¹å®ã®æ»æã³ãŒãã ããèŠãã®ã§ã¯ãªããæ»æã«å¿
èŠãª primitive ã behavior ãèŠãã ãããŠããã®ããžãã¯ããªãŒãã³ã«ããããšã§ãã³ãã¥ããã£å
šäœã®é²åŸ¡åãåºäžãããã ããã¯ãçŸä»£ã®ã»ãã¥ãªãã£éçšã«ãããŠãšãŠãéèŠãªèãæ¹ã§ãã æ»æè
ã¯ã³ãŒãã®èŠãç®ãå€ããããŸãã ããããrootæš©éãåãããã«å¿
èŠãªè¡åã®æµãã¯ãå®å
šã«ã¯é ãã«ããã§ãã Elastic Security ã¯ããã®æµããããŒã¿ããèŠã€ããããã®ãã©ãããã©ãŒã ã§ãã ãããŠããã®æ€ç¥ããžãã¯ã ãªãŒãã³ã«ãéæã«ãã³ãã¥ããã£ãšå
±ã«é²åãããŠãã ã®ããElastic ã®å€§ããªåŒ·ã¿ã§ãã åèãªã³ã¯ Elastic Security Labs åæããã°: Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild Elastic ã®æ€ç¥ã«ãŒã«ãªããžããª: elastic/detection-rules (GitHub) CISA Known Exploited Vulnerabilities Catalog: CISA KEV ãã®èšäºã¯ãElastic Security Labs ãå
¬éããè±èªããã°ãCopy Fail and DirtyFrag: Linux Page Cache Bugs in the Wildããããšã«ãæ¥æ¬ã®Elasticå©çšè
åãã«æŽçã»è£è¶³ãããã®ã§ãã The post Copy Fail / DirtyFrag ãæ€ç¥ããïŒLinux ã«ãŒãã«ã® page cache æ»æãš5ã€ã®æ€ç¥ã«ãŒã« first appeared on Elastic Portal .
ã¯ããã« ãæšæ¶ åããŸããŠãã¯ã©ãŠãã€ã³ãã°ã¬ãŒã·ã§ã³éšæå±ã€ã³ã¿ãŒã³çã®å·èŸºã§ããä»åã¯ãITåå¿è
ã®ç§ããAWSãçšããŠåããŠã®ã¢ããªéçºã«åãçµãã éçšãèšäºã«ããŠãŸãšããŠã¿ãŸããïŒã¢ããªéçºãããã°å·çãšãã«åããŠã®çµéšã§ãã®ã§èšå¿µãšããŠããŸãç§ãšåãããã«æç³»æªçµéšããITæ¥çã«é£ã³èŸŒãæ¹ã
ã®å©ãã«ãªãã°ãããªãšããæãã蟌ããŠå¯çš¿ãããŠããã ããŸãã
























