- TOP
- ã¿ã°äžèЧ
- Ubuntu
Ubuntu
ã€ãã³ã
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã
ãã¬ãžã³
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã
æè¡ããã°
ããã«ã¡ã¯ãæšå¹ŽåºŠãŸã§ç€ŸäŒäººå€§åŠé¢çïŒä¿®å£«èª²çšïŒãšããŠåŠã³ãç¡äºåæ¥ãã Hunachi ã§ã ð ç ç©¶çæŽ»ã®äžã§ã SICS 2026 ãš DEIM 2026 ã«åå ããè«æã®å·çãçºè¡šããã¹ã¿ãŒçºè¡šãããŠããŸããã ç§ã®ç ç©¶å
容ã¯ãAndroidæèŒç«¯æ«ã§ã® pKVM ç°å¢ã䜿ã£ãã»ãã¥ã¢ãªå£°çŽèªèšŒã®å®è£
ãšè©äŸ¡ãã§ã ð ãã®ããã°ã§ã¯ã ç§ãç ç©¶ã§æ±ã£ãŠãã pKVM ã£ãŠãªã«ïŒ ã©ããªç ç©¶ãããŠããã®ãïŒãã£ããïŒ åŠäŒã«åå ããããè«æãæžããŠçºè¡šããŠã¿ãŠã®ææ³ 瀟äŒäººå€§åŠé¢çãããŠã¿ãææ³ 以äžã®4 æ¬ç«ãŠã§ãç§ã®ç ç©¶ã倧åŠé¢ç掻ã«ã€ããŠç޹ä»ããŠãããŸãã SCISã¯åœé€šéå¬ã§ããããã®æã«é£ã¹ããã£ãæ± ð pKVM ã£ãŠãªã«ïŒ ã¢ãã€ã«ç«¯æ«ã§ããã»ãã¥ã¢ãªå®è¡ç°å¢ããæ¬²ãã æè¿ã®ã¹ããŒããã©ã³ã§ã¯ãçäœèªèšŒã»æ±ºæžã»ãªã³ããã€ã¹ AIïŒGemini Nano ãªã©ïŒãšãæ©å¯æ§ã®é«ãåŠçã端æ«äžã§åããå Žé¢ãã©ãã©ãå¢ããŠããŸãããã Android ã§ã®ã»ãã¥ã¢ãªç°å¢ãšããŠã¯ 2014 幎ãã Trusty TEE ïŒTrusted Execution EnvironmentïŒãšãã ARM TrustZone ããŒã¹ã®éé¢ç°å¢ã䜿ãããŠããŸãããAndroid ã®äžè¬çãªã¢ããªãåäœããç°å¢ïŒ REE: Rich Execution Environment ïŒãšã¯ãããŒããŠã§ã¢ã¬ãã«ã§åé¢ãããã»ãã¥ã¢ãªç°å¢ã§ãããã®ãããå
ç¢ãªã»ãã¥ãªãã£ãå®çŸã§ããŸãã ãã ã TEE ã«ã¯ä»¥äžã®åŒ±ç¹ããããŸãã å©çšã§ããã¡ã¢ãªã æ° MB çšåºŠ ãšãšãŠãå°ãã éçºã®ããŒãã«ããããªãã«é«ã 端æ«ã®ãã³ããŒã«ãã£ãŠã»ãã¥ãªãã£ã®è³ªããŸã¡ãŸã¡ ç¹ã«å©çšã§ããã¡ã¢ãªãå°ãªãã®ã§ãDNN ã¢ãã«ãªã©ãåããã®ã¯å€§å€å°é£ã§ã ð pKVM ã®ç»å Ž ããã§ Android 13 ããå°å
¥ããã Android Virtualization FrameworkïŒAVFïŒ ã®äžæ žãšããŠã pKVMïŒProtected KVMïŒ ãšããä»®æ³åæè¡ãçµã¿èŸŒãŸããŸããã ãã£ããèšããšã ããŒã¹ã¯ Linux ç±æ¥ã® KVM ïŒKernel-based Virtual MachineïŒ ããã«ããã¹ã OS ãããè§Šããªã VMïŒ Protected VM, pVM ïŒããšããæŠå¿µãèŒãã 端æ«ã®ç©çã¡ã¢ãªå®¹éãã£ã±ããŸã§äœ¿ããéé¢ç°å¢ãæã«å
¥ã ãšãããTrusty TEE ã®ã¡ã¢ãªå¶çŽãè§£æ¶ããæ¯èŒçæ°ããæè¡ã§ã ð ã¡ãªã¿ã«æ°å¹Žåãã Pixel ã§ root ãåããã« LinuxïŒArch ã UbuntuïŒãåããã ããšãã話é¡ãç®ã«ããæ¹ãããããããªãã§ãããããDanny Lin æ°ã® Nestbox ãšããã¢ããªã§ Android äžã« Linux VM ãç«ã¡äžãããã®ã§ãïŒ åèèšäº ïŒããã®åºç€ã«ãªã£ãŠããã®ããŸãã« pKVM ã§ãããã¹ã OS ããä¿è·ããã VMããšããæ çµã¿ã䜿ãã°ãã»ãã¥ãªãã£çšéã ãã§ãªãæ±çšç㪠OS ã ã£ãŠãã¹ãã§ããŠããŸãããšããã®ãå®èšŒããäžäŸã§ãã pKVM ã®ã¢ãŒããã¯ãã£ããã£ãã ARM ã®ã¢ãŒããã¯ãã£ã§ã¯ãç¹æš©ã¬ãã«ã Exception LevelïŒELïŒ ãšããéå±€ã§åãããŠããŸããpKVM ç°å¢ã«é¢ããéå±€åãã¯ãã®ããã«ãªã£ãŠããŸãã EL2 : pKVM ãã€ããŒãã€ã¶ EL1 : Android Host OS ãš Protected VM EL0 : ãŠãŒã¶ã¢ããªã±ãŒã·ã§ã³ EL2 ã§åã pKVM ã ã¹ããŒãž 2 ããŒãžããŒãã« ã䜿ã£ãŠããã¹ã OS ããã® pVM ã¡ã¢ãªãžã®ã¢ã¯ã»ã¹ãç©ççã«é®æããŸããããã« IOMMU ã䜿ãããšã§ãDMA ããã€ã¹çµç±ã®äžæ£ã¢ã¯ã»ã¹ããããã¯ããŠãããŸãã ãŸããpKVMäžã§åããããã°ã©ã ã¯C/C++ã§æžãå¿
èŠããããŸãããTEEåãã¢ããªã®éçºã«æ¯ã¹ãã°å®¹æã§ãã ã»ãã¥ã¢ãªç°å¢ãæãç«ãããä»çµã¿ pKVMïŒAVFïŒã®åããšããã¯ããã ã¡ã¢ãªãéé¢ããã ããããªãç¹ã§ãã pvmfw ïŒProtected VM FirmwareïŒããã€ããŒãã®çœ²åãæ€èšŒããŠæ¹ããæ€ç¥ DICE ïŒDevice Identifier Composition EngineïŒãããã³ã«ã§ pVM ããšã®ã·ãŒã¯ã¬ãããå°åº DICEã§å°åºããã·ãŒã¯ã¬ããããsealing secretãçæããããã«sealing keyãäœæããŠæ°žç¶ããŒã¿ãªã©ãæå·å pVM çµäºæã«ã¯ãã€ããŒãã€ã¶ãã¡ã¢ãªããŒãžããŒãã¯ãªã¢ããŠæ®ç鲿¢ ã€ãŸããã³ãŒãã®æ£åœæ§ â èµ·åæã®ã·ãŒã¯ã¬ãã â æ°žç¶ããŒã¿ â çµäºæã®æ®ç鲿¢ ãŸã§äžè²«ããŠãã€ããŒãã€ã¶ãã±ã¢ããŠãããããšããèšèšã§ãã ãã㊠2025 幎 8 æãGoogle ã pKVM ã§ SESIP Level 5 èªèšŒãååŸãããšçºè¡šããŸãã ð SESIPïŒSecurity Evaluation Standard for IoT PlatformsïŒã¯ IoT ããã€ã¹åãã»ãã¥ãªãã£è©äŸ¡åºæºã§ãLevel 5 ã¯æé«ã¬ãã«ã§ãã å€§èŠæš¡æ¶è²»è
åãã«å±éããããœãããŠã§ã¢ã»ãã¥ãªãã£ã·ã¹ãã ãšããŠååŸããã®ã¯äžçå ã§ãææ°ãã€ããªãã»ãã¥ã¢ãªæè¡ã§ããããšãããããŸãïŒ Google Online Security Blog ïŒã ç§ã®ç ç©¶ããã£ãã ãã£ãããš ããããã¯èªåã®ç ç©¶ãããªããã£ãã玹ä»ããŸãã ã¿ã€ãã«ã¯ã Google Tensor æèŒç«¯æ«ã® pKVM ã«ãããã»ãã¥ã¢ãªé³å£°åŠçããã³å£°çŽèªèšŒã®å®è£
ææ³ãšèª²é¡ã®æ€èš ãã§ãã è«æã¯ãã¡ãããèªããŸã ð DEIM2026 3D-01 ãããç°¡åã«èšããšã ïŒpKVMç°å¢ïŒäžã§è©±è
èå¥ã®DNNã¢ãã«ãåãããå®çšå¯èœãªåŠçé床ã§åäœãã声çŽèªèšŒã·ã¹ãã ã¢ããªãå®çŸ pKVM ã®ã¡ã¢ãªã¢ã¯ã»ã¹ç¹æ§ã现ããæž¬å® ææ¡ã·ã¹ãã ã®èªèšŒç²ŸåºŠã»åŠçæéã»pKVMã®VM èµ·åæéãªã©ãå€è§çã«è©äŸ¡ ãè¡ã£ãè«æã§ãã ãããŠãããããããšã«ããã®çºè¡šã§ DEIM 2026 åŠçãã¬ãŒã³ããŒã·ã§ã³è³ ãããã ããŸãã ð äžç·ã«ç ç©¶ãé²ããŠãããå
±èã®å
çæ¹ãã³ã¡ã³ãããã ãã£ãçãããæ¬åœã«ããããšãããããŸãã ð ãŸã ãŸã æ¹åã®äœå°ãããããããç ç©¶å
容ã§ãããèå³ã®ããæ¹ã¯è«æãèªãã§ãããããšå¬ããã§ã ð åŠäŒã®ææ³ SICS ã«åå ããææ³ SICSã¯ã以åã¯æå·ç³»ã®çºè¡šãå€ãã£ãããã§ãããæè¿ã¯åŸåãå€ãã£ãŠããããã§ããã»ãã¥ãªãã£é¢é£ã®çºè¡šã§ã¯ãé«ã¬ã€ã€ã®è©±ãå€ãèŠãããŸãããç¹ã«LLMã®ã»ãã¥ãªãã£ãç ç©¶æ¹æ³ã«é¢ããè¬æŒãçºè¡šãå°è±¡çã§ãããæå
端ã®LLMã®ç ç©¶ãããŠããæ¥æ¬äººç ç©¶è
ãããããšããLLMã®ã»ãã¥ãªãã£ã®ç ç©¶ãã©ããŸã§é²ãã§ãããã®è©±ãèãããšãã§ããé¢çœãã£ãã§ãã DEIM ã«åå ããææ³ ããããã®åŠçãããåå ããŠããåŠäŒã§ãè²ã
ãªç ç©¶ã®çºè¡šããã¹ã¿ãŒçºè¡šãèŠãããšãã§ããŸãããç¹ã«åæ¥ã«ãªã¢ãŒãéå¬ã ã£ãã®ã§ã瀟äŒäººã®ç§ã«ãšã£ãŠå€§å€å¬ããã£ãã§ããLINEã€ããŒããã®DBã®è©±ãªã©ãè峿·±ãèãããŠããã ããŸããã æè¿ã®ç ç©¶ã¯ããã¯ãLLMé¢é£ãå€ããèªåãç ç©¶ã§LLMãæ±ãããããããçšåºŠã¯è©³ãããªããªããšãããªããšæããŸããã è«æå·çã»çºè¡šã»ãã¹ã¿ãŒçºè¡šãããŠã¿ãææ³ åŠéšæä»£ã®ç ç©¶ããã®ãŸãŸç¶ããªãã£ãããšããããææãåºããç ç©¶ããŒãã«ãã©ãçããŸã§æéããããããšãŠã倧å€ã§ãããäžæ¹ã§ãå
çæ¹ã®å©èšãAIã®æŽ»çšã«ãããå
è¡ç ç©¶ãææ°æè¡ã®èª¿æ»ãå¹çåã§ããŸããããã®çµæãææãåºããŠããã£ãã§ãã ãŸãè«æãå·çããã«ããããæ
£ããªãéšåã«ã€ããŠã¯ãAIã«æå©ãããŠããããªããå·çããŸããã4幎åã®åŠéšæä»£ãé«å°æä»£ã«è«æãæžããæãšæ¯ã¹ãŠãLaTeXã®ãšã©ãŒã«æ©ãŸãããæéãã誀åè±åã®ä¿®æ£ã«ãããæéããã»ãŒãŒãã«ãªããŸãããæ¬åœã«æ¥œãªæä»£ã«ãªã£ããªãšæããŸãã çºè¡šã§ã¯å³ããã®è³ªåãããã ãããšããããŸãããããã以äžã«å¬ããããšããããŸããã䌌ãç ç©¶ãããŠããæ¹ãå°ãªãã«ãããããããç¹ã«DEIMã§ã¯ç§ã®ç ç©¶ã«èå³ãæã£ãŠè³ªåããŠãã ããæ¹ãå€ãããšãŠãå¬ããã£ãã§ãã 人ã«èªåã®ç ç©¶å
容ãäŒããããšã¯ã瀟äŒäººã«ããããã¬ãŒã³ããŒã·ã§ã³ãè¡ãéã«ã掻ããããªãšæããŸããã 瀟äŒäººå€§åŠé¢çïŒä¿®å£«èª²çšïŒãããŠã¿ãææ³ 倧åŠã®ææãDé²ããŠããåæã倫ã®å®¶äºãµããŒãããã£ãããããã忥ã§ããŸãããé¢ä¿è
ã®çããã«æè¬ãããããŸããã 人ã«ããããã§ããããšãããšããšãŠãå¿ããçæŽ»ã¹ã¿ã€ã«ã«ãªããããç ç©¶ãè¶£å³ãªäººä»¥å€ã«ã¯ãããããã«ããã§ãããã ãAIã®æŽ»çšã§èª¿æ»ãæç« å·çã容æã«ãªã£ãä»ã®æä»£ã ãããããããã£ã¬ã³ãžã¯å¯èœã ããšæããŸãã ç§ã®æããã¡ãªããã»ãã¡ãªãã ã¡ãªããã¯ãééçãªåé¡ã§å°ãã«ããããšã§ãããããããªçç±ããããç«ãšæ®ãããŠããèªåã«ã¯åããªããšããéžæè¢ããªãã£ãããã瀟äŒäººåŠçãéžã³ãŸãããåãã€ã€åŠçã§ããããšãèš±ããŠããã倧åŠã®ææã«ã¯æè¬ãããããŸããããã®ãããã§ç«ãšæ®ããã€ã€åŠè²»ãå®å®ããŠæãããšãã§ããŸããã ãã¡ãªããã¯ä»¥äžã®ãšããã§ãã 倧åŠä»¥å€ã®ããšããããã©ã€ããŒããªæéãããªãå°ãªããªãããš ç ç©¶ã«æéãè²»ããå¿
èŠãããã®ã¯ãã¡ããã®ããšãåŠäŒãææ¥ã®åå ã§æçµŠãæ¶è²»ãããŸã ä»äºã倧åŠãå¿ããææã«ã¯ç¡ç æé以å€ã¯ããœã³ã³ã®åã«ããããšãããããªäžå¥åº·ãªçæŽ»ãæ¥åžžã«ãªãããš åŠçãããçæŽ»ãã§ããªãããš ç§ã®å Žåã¯ã倧åŠã«è¡ãæéãåããåšå®
ã§ç ç©¶ãè¡ãªã£ãŠããé¢ä¿ã§ãå人ãšç 究宀ã§ãããã¹ããããã飲ã¿äŒãå宿ãžã®åå ãªã©ã¯ã§ããŸããã§ããã ãŸãç§ã¯ãåŠéšæä»£ã«å€§åŠé¢ã®ææ¥åäœãååŸã§ããå¶åºŠã掻çšããŠããããã倧ããªåé¡ã¯ãããŸããã§ããããã ãã倧åŠãåäœã®ååŸç¶æ³ã«ãã£ãŠã¯ãææ¥ã®ããã«æçµŠã䜿ãå¿
èŠãåºãŠãããããããŸãããããã«ã倧åŠçãããçæŽ»ãéããªãã®ã¯ãã£ãããªããšæãããããå人çã«ã¯å¯èœã§ããã°éåžžã®å€§åŠé¢çãšããŠéãã»ãããããšæããŸãã â» ç§ã®å€§åŠç掻ã®ã»ãšãã©ã¯ã³ããã§ãªã³ã©ã€ã³ã ã£ãé¢ä¿ã§å€§åŠç掻ããŸãšãã«ããããšããªãã®ã§æèŠãåã£ãŠããå¯èœæ§ããããŸãã ãã ãäºæ
ããã瀟äŒäººã«ãªãå¿
èŠããã人ããã§ã«ç€ŸäŒäººã®æ¹ã§ãç ç©¶ããããã»ç¶ããã人ã¯ååé 匵ã£ãŠã¿ã䟡å€ããããšæãã®ã§å¿æŽããŠããŸã ð© ãããã« åŒãç¶ãpKVMãç ç©¶é¢é£ã®å匷ã¯ç¶ããããšæã£ãŠããŸã ð§âð æåŸãŸã§èªãã§ãã ãã£ãŠããããšãããããŸããïŒ
ã¯ããã« ååã¯æ¬ã·ãªãŒãºã®ç¬¬äžåŒŸãšããŠãæ
å ±ã»ãã¥ãªãã£ã«é¢ããåºæ¬æŠå¿µãæŽçããããŸã èªãã§ããªãæ¹ã¯ãå
ã«ãã¡ãã確èªããŠããã ããããä»åã¯ãå®éã®ãããã¬ãŒã·ã§ã³ãã¹ãïŒPenetration TestïŒã®å®æœãéããŠãæ»æè
ã®èŠç¹ããæ
å ±ã»ãã¥ãªãã£è
åšãžã®çè§£ãå°ãæ·±ããŠããã ãããšãçããšããŠãããçè
ããäŒãããå
容ãå€ããããèšäºã¯3ã4åã«åããŠèª¬æããäºå®ã ãŸããæ¬ã·ãªãŒãºã®ç®çãæ¹ããŠè¿°ã¹ããšããããã¬ãŒã·ã§ã³ãã¹ããã®ãã®ã®å®æœæ¹æ³ãäžå¿ã«è§£èª¬ããããšã§ã¯ãªãããããã¬ãŒã·ã§ã³ãã¹ããéããŠæ»æè
ãã©ããçããããã®ããæç¢ºã«ããæ¥ã
ã®éçšæ¥åã®äžã§æœåš
Linuxã¯ãå€ãã®äŒæ¥ã·ã¹ãã ãã¯ã©ãŠãç°å¢ãã³ã³ããåºç€ã§äœ¿ãããŠããŸãã ãã®ãããLinuxã«ãŒãã«ã«æ·±å»ãªè匱æ§ãèŠã€ãããšã圱é¿ã¯ãšãŠã倧ãããªããŸãã Elastic Security Labs ã¯ãLinuxã«ãŒãã«ã®æš©éææ Œè匱æ§ã§ãã Copy Fail (CVE-2026-31431) ãCopy Fail 2ããã㊠DirtyFrag ãåæããŸããããããã¯ãLinuxã® page cache ã«é¢ä¿ãããã°ãæªçšããéåžžãŠãŒã¶ãŒãã rootæš©é ãååŸã§ããå¯èœæ§ãããæ»æã§ãã ç¹ã« Copy Fail (CVE-2026-31431) ã¯å®éã®æ»æã§æªçšãããããšãå ±åãããŠãããç±³åœCISAã® Known Exploited Vulnerabilities (KEV) ã«ã¿ãã° ã«ã远å ãããŠããŸããKEVã«ã¿ãã°ã«èŒããšããããšã¯ããæºäžã®è匱æ§ãã§ã¯ãªããçŸå®ã«æ»æã§äœ¿ãããŠããè匱æ§ãã§ããããšãæå³ããŸããç±³åœã®é£éŠæ©é¢ã¯æéå
ã®ãããé©çšã矩åä»ããããã¬ãã«ã§ãããæ°éäŒæ¥ã«ãšã£ãŠãåªå
察å¿ãã¹ã匷ãã·ã°ãã«ã§ãã ãã®èšäºã§ã¯ããã®æ»æãã»ãã¥ãªãã£åå¿è
ã«ããããããã«æŽçããªãããElastic Securityãã©ã®ããã«è
åšãåæããæ€ç¥ã«ã€ãªããŠããã®ãããã㊠Elasticãå
¬éããŠããæ€ç¥ã«ãŒã« ã玹ä»ããŸãã ç®æ¬¡ ãŸããäœãå±éºãªã®ãïŒ page cache ãšã¯äœãïŒ page cache corruption ãšã¯ïŒ Copy Fail ã¯äœãããã®ãïŒ DirtyFrag ã¯äœãéãã®ãïŒ â ïž ãããæéèŠïŒCopy Fail ã®ãããã ãã§ã¯äžåå ãªã Elastic ã®åæãéèŠãªã®ãïŒ Elastic ãå
¬éããæ€ç¥ã«ãŒã«5æ¬ 1. Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket 2. Suspicious SUID Binary Execution 3. Suspicious Kernel Feature Activity 4. Namespace Manipulation Using Unshare 5. Privilege Escalation via SUID/SGID 5æ¬ã®ã«ãŒã«ãã©ã飿ºããã Elastic ã®åŒ·ã¿ïŒãã¹ãŠã®æ€ç¥ã«ãŒã«ã GitHub ã§å
¬éãããŠãã ããããªãéèŠãªã®ãïŒ æ¥æ¬ã®ãŠãŒã¶ãŒã«ãšã£ãŠã®æå³ ããžãã¹èŠç¹ã§ãªãéèŠãªã®ãïŒ ãŸãšãïŒElastic Security ã¯ãæ»æã®åœ¢ãã§ã¯ãªããæ»æã®åãããèŠã åèãªã³ã¯ ãŸããäœãå±éºãªã®ãïŒ ä»åã®ãã€ã³ãã¯ãæ»æè
ãLinuxäžã§ rootæš©é ãååŸã§ããå¯èœæ§ãããããšã§ãã rootãšã¯ãLinuxã«ãããæãåŒ·ãæš©éãæã€ãŠãŒã¶ãŒã§ãã ããšãããªãããã«å
šäœã®ãã¹ã¿ãŒããŒãæã€ç®¡çè
ã®ãããªååšã§ãã éåžžãŠãŒã¶ãŒã¯ãèªåã®éšå±ãèš±å¯ãããå Žæã«ããå
¥ããŸããã ãããrootã¯ãã·ã¹ãã å
šäœã®èšå®å€æŽããã¡ã€ã«ã®èªã¿æžããããã»ã¹ã®åæ¢ããŠãŒã¶ãŒäœæãªã©ãå€ãã®æäœãã§ããŸãã ã€ãŸããæ»æè
ãrootæš©éãåããšã次ã®ãããªããšãå¯èœã«ãªããŸãã æ©å¯ãã¡ã€ã«ãèªã ã»ãã¥ãªãã£ããŒã«ãæ¢ãã ãã«ãŠã§ã¢ãèšçœ®ãã ãã°ãæ¹ãããã ä»ã®ã·ã¹ãã ãžäŸµå
¥ããè¶³ããããäœã ããã¯ãåãªãã1å°ã®LinuxãµãŒããŒã®åé¡ãã§ã¯ãããŸããã äŒæ¥ã®ã¯ã©ãŠãç°å¢ãã³ã³ããåºç€ãæ¥åã·ã¹ãã å
šäœã«åœ±é¿ããå¯èœæ§ããããŸãã page cache ãšã¯äœãïŒ ä»åã®æ»æãçè§£ããããã«ããŸã page cache ãçè§£ããå¿
èŠããããŸãã page cacheãšã¯ãLinuxããã¡ã€ã«ã¢ã¯ã»ã¹ãéãããããã«äœ¿ãã¡ã¢ãªäžã®äžæçãªä¿ç®¡å Žæã§ãã ããšãã°ã峿žé€šãã€ã¡ãŒãžããŠãã ããã æ¬æ£ã«ããæ¬ãããã£ã¹ã¯äžã®ãã¡ã€ã«ãã ãšããŸãã ã§ããããèªãŸããæ¬ãæ¯åæ¬æ£ãŸã§åãã«è¡ãã®ã¯é¢åã§ãã ããã§å³æžé€šå¡ã¯ãããäœ¿ãæ¬ã®ã³ããŒãæºã®äžã«çœ®ããŠãããŸãã ãã®ãæºã®äžã®ã³ããŒãããLinuxã§ãã page cache ã§ãã ããšã Linux æ¬æ£ã®æ¬ ãã£ã¹ã¯äžã®ãã¡ã€ã« æºã®äžã®ã³ã㌠page cache 峿žé€šå¡ Linuxã«ãŒãã« æ¬ãèªã人 ã¢ããªã±ãŒã·ã§ã³ éåžžãpage cacheã¯äŸ¿å©ãªä»çµã¿ã§ãã ãã¡ã€ã«ãæ¯åãã£ã¹ã¯ããèªããããã¡ã¢ãªããèªãã æ¹ãéãããã§ãã ããããä»åã®ãããªè匱æ§ã§ã¯ããã®ãã¡ã¢ãªäžã®ã³ããŒããæªçšãããŸãã page cache corruption ãšã¯ïŒ page cache corruption ãšã¯ãç°¡åã«èšããšãLinuxãä¿¡é ŒããŠããã¡ã¢ãªäžã®ãã¡ã€ã«ã³ããŒãäžæ£ã«æžãæããããšã§ãã éèŠãªã®ã¯ãæ»æè
ãå¿
ããããã£ã¹ã¯äžã®æ¬ç©ã®ãã¡ã€ã«ãæžãæããããã§ã¯ãªãããšããç¹ã§ãã æ¬ç©ã®ãã¡ã€ã«ã¯å€ãã£ãŠããªãããã«èŠããŸãã ããããLinuxãå®éã«äœ¿ãã¡ã¢ãªäžã®ã³ããŒã ããå£ãããŠããå¯èœæ§ããããŸãã ããã¯éåžžã«åä»ã§ãã ãªããªãããã¡ã€ã«ã®æ¹ãããã§ãã¯ãããŠãããã£ã¹ã¯äžã®ãã¡ã€ã«ã¯æ£åžžã«èŠããããšãããããã§ãã äžæ¹ã§ãã·ã¹ãã ã¯å£ãããpage cacheã®å
容ã䜿ã£ãŠããŸãå¯èœæ§ããããŸãã ããšãããªããäŒç€Ÿã®æ£åŒãªå¥çŽæžã¯é庫ã®äžã§ç¡äºãªã®ã«ãæ
åœè
ãæºã®äžã«çœ®ããŠããã³ããŒã ãããã£ããæžãæããããŠããç¶æ
ã§ãã æ
åœè
ããã®ã³ããŒãä¿¡ããŠåŠçãé²ãããšãééã£ã倿ã«ã€ãªãããŸãã Copy Fail ã¯äœãããã®ãïŒ Elasticã®èª¬æã«ãããšãCopy Fail 㯠Linuxã«ãŒãã«ã®æå·åŠçïŒauthencesn ãã³ãã¬ãŒãïŒã«é¢ä¿ããããžãã¯ãã°ã§ããAF_ALG ãš splice() ãšãã Linux ã®æ£èŠæ©èœãçµã¿åãããããšã§ãèªã¿åãå¯èœãªãã¡ã€ã«ã®page cacheã«å¯ŸããŠãå¶åŸ¡ããã4ãã€ãã®æžã蟌ã¿ãè¡ãããšèª¬æãããŠããŸãã ããã§éèŠãªã®ã¯ãããã setuidãã€ã㪠ã«å¯ŸããŠäœ¿ããããšããç¹ã§ãã setuid ãã€ããªãšã¯ å®è¡ãããŠãŒã¶ãŒã§ã¯ãªãããã¡ã€ã«ã®ææè
ã®æš©éã§åãç¹æ®ãªããã°ã©ã ã§ãã ããšãã° /usr/bin/su ã¯ææè
ãrootã§ãsetuid ãèšå®ãããŠãããããèªèšŒåŠçãªã©ã®äžéšã®åŠçãrootæš©éã§å®è¡ã§ããŸãããã¡ãããéåžžã¯ãã¹ã¯ãŒã確èªãªã©ã®èªèšŒãããããã誰ã§ãèªç±ã«rootã«ãªããããã§ã¯ãããŸããã ãããããã®ãrootæš©éã§åãéšåããããæ»æè
ã®æšçã«ãªããŸããCopy Fail ã®ãããªæ»æã§ã¯ããã£ã¹ã¯äžã®ãã¡ã€ã«ãçŽæ¥æžãæããã®ã§ã¯ãªããpage cacheäžã®ãã€ããªå
容ãå£ãããšã§ãrootæš©éã§å®è¡ãããåŠçãæªçšããããšããŸãã å®éã« Copy Fail ã§ã¯ã/usr/bin/su ã®ãããªsetuidãã€ããªã®ã¡ã¢ãªäžã®èŠãæ¹ãå£ãã ãã£ã¹ã¯äžã®ãã¡ã€ã«ã倿Žããã«æš©éææ Œ ã«ã€ãªããããšãã§ããŸããå
¬éãããŠããæ»æã³ãŒãã¯ãããã732ãã€ãã®Pythonã¹ã¯ãªããã§ãUbuntuãAmazon LinuxãRHELãSUSE ãšãã£ãäž»èŠãã£ã¹ããªãã¥ãŒã·ã§ã³ã§åäœããŸãã ããã§éèŠãªã®ã¯ãæ»æè
ããæªãããã«ãŠã§ã¢ãã ãã䜿ã£ãŠããããã§ã¯ãªãããšã§ãã AF_ALG ã splice() ããLinuxã«ååšããæ£èŠã®ä»çµã¿ã§ãã ã€ãŸãæ»æã¯ãå®å
šã«å€éšããèŠãŠæããã«æªããåäœã ãã§æãç«ã£ãŠããããã§ã¯ãããŸããã æ£èŠã®Linuxæ©èœãçµã¿åãããŠãã«ãŒãã«ã®çްãããã°ãçªããŠããŸãã ããããæ€ç¥ãé£ããããŸãã DirtyFrag ã¯äœãéãã®ãïŒ DirtyFragããpage cache corruption ãæªçšãã Linuxã«ãŒãã«ã®æš©éææ Œæ»æã§ãã åºæ¬ã®èãæ¹ã¯ Copy Fail ãšäŒŒãŠããŸããã æ»æçµè·¯ããããã¯ãŒã¯ã¹ã¿ãã¯ã«åºãã£ãŠãã ç¹ã倧ããç°ãªããŸãã Elasticã®ããã°ã«ãããšãDirtyFragã«ã¯2ã€ã®çµè·¯ããããŸãã çµè·¯ 䜿ãããä»çµã¿ æ»æå¯Ÿè±¡ çµæ ESPãã¹ AF_NETLINK çµç±ã®XFRM SA /usr/bin/su suãæå°éã®root shell ELFã§äžæžã RxRPCãã¹ïŒãã©ãŒã«ããã¯ïŒ AF_RXRPC + pcbc(fcrypt) /etc/passwd rootã®ãã¹ã¯ãŒããã£ãŒã«ããã¯ãªã¢ /etc/passwd ã®rootãã¹ã¯ãŒããã£ãŒã«ããã¯ãªã¢ããããšãç°å¢ã«ãã£ãŠã¯ãã¹ã¯ãŒããªãã§rootãšããŠèªèšŒãéã£ãŠããŸãå¯èœæ§ããããŸãã å®éã®æåã¯ãPAM ã SSH ã®èšå®ãshadow ãã¡ã€ã«ã®éçšç¶æ³ã«ãã£ãŠå€ãããŸãããããããããã«ããŠããrootèªèšŒã®åæãå£ãéå€§ãªæ¹ããã§ããããšã«å€ããã¯ãããŸããã ããã«ãäž¡æ¹ã®çµè·¯ãšãã« unshare(CLONE_NEWUSER | CLONE_NEWNET) ã䜿ã£ãŠ namespace capability ãååŸããåæ®µãå¿
èŠã§ããããã¯ãåŸè¿°ããæ€ç¥ããžãã¯ã§éèŠãªãã€ã³ãã«ãªããŸãã â ïž ãããæéèŠïŒCopy Fail ã®ãããã ãã§ã¯äžåå Elasticã®ããã°ãèŠåããŠããæãéèŠãªãã€ã³ãã¯æ¬¡ã®ããšã§ãã DirtyFrag 㯠algif_aead ã¢ãžã¥ãŒã«ã«äŸåããŸããã ã€ãŸããCopy Fail ã®ç·©åçïŒalgif_aead ãç¡å¹åããïŒã ããé©çšããã·ã¹ãã ã¯ãäŸç¶ãšããŠDirtyFragã«è匱ãªãŸãŸã§ãã ãCopy Fail察çã¯ãã£ãããå®å¿ããšããæã蟌ã¿ããæãå±éºãªç¶æ
ãçã¿ãŸãã äž¡æ¹ã®è匱æ§ã«å¯ŸããŠã ããããç¬ç«ãã察çãå¿
èŠ ã§ãã ãªã Elastic ã®åæãéèŠãªã®ãïŒ ããããããElastic Securityãçè§£ããããã§å€§äºãªãã€ã³ãã§ãã Elasticã¯ãåã«ãç¹å®ã®æ»æã³ãŒããèŠã€ããŸãããããšããèŠæ¹ã ããããŠããŸããã ã»ãã¥ãªãã£ç ç©¶è
ã¯ãæ°ããè匱æ§ãèŠã€ãããšããã°ãã° PoCïŒProof of ConceptïŒ ãšåŒã°ããå®èšŒã³ãŒããå
¬éããŸããããã¯ããã®æ»æãæ¬åœã«å¯èœã§ããããšã瀺ããã¢ã³ãŒããã§ãããé²åŸ¡åŽãè匱æ§ãçè§£ãã察çãæ€èšŒããããã«äœ¿ãããŸãã ããããæ»æè
ã¯ãã®å®èšŒã³ãŒãããã®ãŸãŸã®åœ¢ã§äœ¿ããšã¯éããŸããã Pythonã§æžãããã³ãŒãããGoãRustãCã«æžãæããããšãã§ããŸãã ãã¡ã€ã«åãããã»ã¹åãå€ããããšãã§ããŸããå®è¡æ¹æ³ãå°ãå€ããããšãã§ããŸãã å®éãCopy Fail ã¯ãã§ã« Python / Go / Rust / C / Metasploit ãªã©ãè€æ°ã®èšèªã»ãã¬ãŒã ã¯ãŒã¯ã§å®è£
ãå
¬éãããŠãããDirtyFrag ã Cèšèªçã®å®è£
ãå
¬éãããŠããŸãã ãã®ããã ç¹å®ã®æ»æã³ãŒãã®èŠãç®ã ããæ€ç¥ããŠãããšãå°ãå€ããããã ãã§èŠéãå¯èœæ§ããããŸã ã ElasticãéèŠããŠããã®ã¯ãæ»æã® primitive ãš behavior ã§ãã primitive ãšã¯ãæ»æãæ§æããå°ããªæè¡çãªéšåã®ããšã§ãã ããšãã°ããã«ãžã®äŸµå
¥ã§èãããšãæ»æå
šäœã¯ãäžæ£äŸµå
¥ãã§ãã ãã®äžã®primitiveã¯ã次ã®ãããªå°ããªè¡åã§ãã éµãããéãã ç£èŠã«ã¡ã©ãé¿ãã è£å£ã䜿ã 管ç宀ã«å
¥ã Linuxæ»æã§èšãã°ãprimitiveã¯æ¬¡ã®ãããªãã®ã§ãã AF_ALG ã䜿ã splice() ã䜿ã page cache ãå£ã setuidãã€ããªãæªçšãã unshare() ã§namespaceãäœã Elasticã¯ãæ»æã³ãŒããã®ãã®ã ãã§ãªããããããæ»æã®éšåãè¡åãã¿ãŒã³ãèŠãããšããŠããŸãã ããã¯ãçŸä»£ã®ã»ãã¥ãªãã£æ€ç¥ã«ãããŠéåžžã«éèŠã§ãã Elastic ãå
¬éããæ€ç¥ã«ãŒã«5æ¬ ä»å Elastic Security Labs ã¯ãCopy Fail / DirtyFrag ã«å¯Ÿå¿ããæ€ç¥ã«ãŒã«ãå
¬éããŸããã ããã§éèŠãªã®ã¯ã ãããã®ã«ãŒã«ã¯ãã¹ãŠ GitHub ã§èª°ã§ãèŠããã ãšããããšã§ãïŒåŸè¿°ïŒã 以äžã5æ¬ã®ã«ãŒã«ããããããäœãæ€ç¥ãããããç°¡æœã«ç޹ä»ããŸãã 1. Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket äœãæ€ç¥ããã: érootãŠãŒã¶ãŒã AF_ALG ãœã±ããïŒæå·åŠççšã®ç¹æ®ãªãœã±ããïŒãš splice() ãçµã¿åãããŠäœ¿ãããã®åŸ root æš©éã®ããã»ã¹å®è¡ãã·ã§ã«èµ·åã«ã€ãªããæµãã æ»æã®ã©ãã§å¹ãã: Copy Fail ã®æãæ žå¿çãªããªããã£ããçŽæ¥æããŸãã åææ¡ä»¶: ãã®ã«ãŒã«ãæå¹ã«æŽ»çšããã«ã¯ãLinux äžã§ auditd ç³»ã®ãã°ã Elastic ã«åã蟌ãã§ããå¿
èŠããããŸããå
·äœçã«ã¯ãElastic Agent ã® Auditd Manager integration ã Auditbeat ã®èšå®ãå¿
èŠã§ãããããããªãç°å¢ã§ã¯ãsocket ã splice ã®ãããªäœã¬ãã«ãª syscall ã®åãã¯èŠããŸããã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 2. Suspicious SUID Binary Execution äœãæ€ç¥ããã: suãsudoãpkexecãpasswd ãªã©ã®SUIDãã€ããªããäžå¯©ãªèŠªããã»ã¹ïŒPythonãRubyãªã©ã®ã¹ã¯ãªããã©ã³ã¿ã€ã ã/tmp ã /dev/shm ãšãã£ããŠãŒã¶ãŒæžã蟌ã¿å¯èœãã¹ããã®å®è¡ïŒãããæå°éã®åŒæ°ã§åŒã³åºããããã¿ãŒã³ã æ»æã®ã©ãã§å¹ãã: Copy Fail / DirtyFrag ã®äž¡æ¹ã® æçµæ®µé ïŒrootæš©éååŸã®ç¬éïŒãæããŸããauditd ãå
¥ã£ãŠããªãç°å¢ã§ããããã»ã¹å®è¡ã€ãã³ãã ãã§åäœãããããé©çšç¯å²ãåºãã®ãç¹åŸŽã§ãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 3. Suspicious Kernel Feature Activity äœãæ€ç¥ããã: sysctl ãªã©ã«ããã«ãŒãã«æ©èœã®äžå¯©ãªæäœãæ»æè
ãé²åŸ¡æ©æ§ãç¡å¹åããããã«ãŒãã«åäœã倿ŽãããããåããæããŸãã äœçœ®ã¥ã: ãã®ã«ãŒã«ã¯ Copy Fail / DirtyFrag å°çšãšãããããæ»æè
ãã«ãŒãã«æ©èœãäžå¯©ã«æäœããåããåºãèŠãããã®è£å©çãªæ€ç¥ã§ããä»åã®ãããªã«ãŒãã«æªçšã®æèã§ããé¢é£ããäžå¯©ãªæäœãèŠã€ããããã®è¿œå ã¬ã€ã€ãŒãšããŠåœ¹ç«ã¡ãŸãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 4. Namespace Manipulation Using Unshare äœãæ€ç¥ããã: unshare ã³ãã³ãã syscall ã«ãããŠãŒã¶ãŒããŒã ã¹ããŒã¹ïŒç¹ã« CLONE_NEWUSER | CLONE_NEWNETïŒã®äœæãšããã®çŽåŸã® root ããã»ã¹å®è¡ã»setuid(0) ã®çžé¢ã æ»æã®ã©ãã§å¹ãã: DirtyFrag åºæã®å段 ãæããŸããDirtyFrag 㯠namespace ã®ååŸãå¿
é ãªã®ã§ããããæœ°ããšæ»æãã§ãŒã³å
šäœãæç«ããªããªããŸãã åææ¡ä»¶: ãã®ã«ãŒã«ããsyscall ã¬ãã«ã®æ€ç¥éšå㯠auditd ç³»ã®ãã°ãå¿
èŠã§ããããã»ã¹å®è¡ã€ãã³ãã®éšå㯠Elastic Agent / Endpoint ã§ååŸã§ããŸãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 5. Privilege Escalation via SUID/SGID äœãæ€ç¥ããã: SUID/SGIDãã€ããªãæªçšããæš©éææ Œå
šè¬ã®ãã¿ãŒã³ãCopy Fail / DirtyFrag ã«éãããé¡äŒŒã®æš©éææ Œææ³ãåºãã«ããŒããŸãã æ»æã®ã©ãã§å¹ãã: æ±çšçãªæš©éææ Œã®æçµæ®µéãCopy Fail / DirtyFrag ã®æŽŸçãããŸã å
¬éãããŠããªãé¡äŒŒææ³ã«ãåããä¿éºçãªã«ãŒã«ã§ãã ð GitHubã§ã«ãŒã«ã®å®ç©ãèŠã 5æ¬ã®ã«ãŒã«ãã©ã飿ºããã ãããã®ã«ãŒã«ã¯ãããããç¬ç«ããŠåããŸããã æ»æã®ç°ãªã段éãå€å±€çã«ã«ããŒããèšèš ã«ãªã£ãŠããŸãã æ»æè
ã1ã€ã®æ®µéãåé¿ããŠããå¥ã®æ®µéã§æ€ç¥ã§ãã å€å±€é²åŸ¡ïŒdefense in depthïŒ ã®èãæ¹ã§ãã Elastic ã®åŒ·ã¿ïŒãã¹ãŠã®æ€ç¥ã«ãŒã«ã GitHub ã§å
¬éãããŠãã ããã§ãElastic Security ã®éèŠãªç¹åŸŽããäŒãããŸãã Elastic ã¯ãåçšè£œåã®æ€ç¥ã«ãŒã«ããã¹ãŠ GitHub ã§å
¬éããŠããŸãã ãªããžããªã¯ãã¡ãã§ãïŒ ð elastic/detection-rules ãã®ãªããžããªã«ã¯ãElastic Security ã§äœ¿ãããæ€ç¥ã«ãŒã«ã TOML 圢åŒã§æ ŒçŽãããŠããã 誰ã§ãèªç±ã«é²èЧã»Forkã»ã³ã¡ã³ãã»Pull Request å¯èœ ã§ãã ããããªãéèŠãªã®ãïŒ ã»ãã¥ãªãã£éçšã«ãããŠãæ€ç¥ã«ãŒã«ã®äžèº«ãããããªãããšã¯ãããã€ãã®åé¡ãåŒãèµ·ãããŸãã æ€ç¥ã«ãŒã«ãèŠãããªãå Žå æ€ç¥ã«ãŒã«ãå
¬éãããŠããå Žå ã¢ã©ãŒããåºããããªãçºç«ãããããããªã ã«ãŒã«ã®ããžãã¯ãèªãã§çç±ãçè§£ã§ãã 誀æ€ç¥ãåºãŠãããã¥ãŒãã³ã°ã§ããªã æ¡ä»¶ãèªãã§ãèªç€Ÿç°å¢åãã«äŸå€ã远å ã§ãã ããã³ããŒãä¿¡ãããããªããç¶æ
èªåã§ã¬ãã¥ãŒããŠçŽåŸã§ãã æ€ç¥æŒãããã£ãŠããåå ãããããªã ããžãã¯ã®ç©ŽãçºèŠããæ¹åææ¡ã§ãã ã³ãã¥ããã£ç¥èŠãå
±æãããªã OSSãšããŠã³ãã¥ããã£ã«éå
ã§ãã ãªããæ€ç¥ã«ãŒã«ãå
¬éããŠãããã³ããŒã¯ Elastic ã ãã§ã¯ãããŸãããMicrosoft Sentinel ã Analytics rules ã GitHub ã§å
¬éããŠãããéææ§ã®é«ãã¢ãããŒããåã£ãŠããŸããäžæ¹ãå€ãã®åçš EDR/SIEM 補åã§ã¯æ€ç¥ããžãã¯ãéå
¬éã§ããŠãŒã¶ãŒãã«ãŒã«ã®äžèº«ã確èªã§ããªãããšãçãããããŸãããElastic ã¯æ©ã段éãããã®å
¬éæ¹éãäžè²«ããŠç¶ããŠããç¹ãç¹åŸŽã§ãã æ¥æ¬ã®ãŠãŒã¶ãŒã«ãšã£ãŠã®æå³ æ¥æ¬ã§ã¯ãElastic ãå®å
šã«çè§£ããŠãããšã³ãžãã¢ã¯ãŸã å€ããããŸããã ã ããããã ã«ãŒã«ããªãŒãã³ãœãŒã¹ãšããŠå
¬éãããŠãã ããšã®äŸ¡å€ã¯å€§ããã§ãã è±èªã®ããã°ãå®å
šã«çè§£ã§ããªããŠãã TOMLãã¡ã€ã«ãèªãã°æ€ç¥ããžãã¯ãããã 瀟å
SOCã®ãã¬ããžãšã㊠ã«ãŒã«ãåçµã»æ¹é ããŠåŠã¹ã èªç€Ÿç°å¢ç¹æã®èª€æ€ç¥ã«å¯Ÿã㊠èªåã§äŸå€æ¡ä»¶ã远å ã§ãã æ¥æ¬èªã³ãã¥ããã£ã§ ã«ãŒã«ã®è§£éãè°è«ã§ãã ããžãã¹èŠç¹ã§ãªãéèŠãªã®ãïŒ ãã®è©±ã¯ãã»ãã¥ãªãã£ç ç©¶è
ã ãã®ãã®ã§ã¯ãããŸããã äŒæ¥ã«ãšã£ãŠéèŠãªã®ã¯ã次ã®3ã€ã§ãã 1ã€ç®ã¯ãè¢«å®³ã®æ©æçºèŠã§ãã rootæš©éãåããããšãæ»æè
ã¯ããæ·±ãã·ã¹ãã ã«å
¥ã蟌ããŸããæ©ãæ°ã¥ããã°ã被害ãå°ããã§ããŸãã 2ã€ç®ã¯ãèª¿æ»æéã®ççž®ã§ãã SOCãã»ãã¥ãªãã£æ
åœè
ã¯ãæ¯æ¥å€ãã®ã¢ã©ãŒããèŠãŠããŸããElastic Securityã®ããã«ãæ»æã®æµããèŠããããä»çµã¿ããããšããããã¯äœãèµ·ããŠããã®ãããæ©ãçè§£ã§ããŸãã 3ã€ç®ã¯ãæªç¥ã»å€çš®ãžã®å¯Ÿå¿åã§ãã æ»æè
ã¯æ»æã³ãŒããæžãæããŸããããŒã«åãå€ããŸããå®è¡æ¹æ³ãå€ããŸãã ããããæ»æã«å¿
èŠãªåºæ¬è¡åã¯å€§ããå€ããã«ããã§ãã ã ãããããElasticãéèŠããŠããããµããŸãæ€ç¥ãã¯ãããžãã¹ã«ãšã£ãŠã䟡å€ããããŸãã ãŸãšãïŒElastic Security ã¯ãæ»æã®åœ¢ãã§ã¯ãªããæ»æã®åãããèŠã Copy Fail ã DirtyFrag ã¯ãLinuxã«ãŒãã«ã®çްãããã°ãæªçšããé«åºŠãªæ»æã§ãã ããããåå¿è
åãã«äžèšã§ãŸãšãããªããããèšããŸãã Linuxãé«éåã®ããã«äœ¿ã£ãŠãã page cache ãæªçšããã¡ã¢ãªäžã®ãã¡ã€ã«å
容ãå£ãããšã§ãéåžžãŠãŒã¶ãŒãã rootæš©éãåãæ»æã§ãã ãããŠãElastic Security Labs ã®éèŠãªè²¢ç®ã¯ããããåãªãèåŒ±æ§æ
å ±ãšããŠç޹ä»ããã ãã§ãªãã å®éã®æ€ç¥ã«ãŒã«ã«èœãšã蟌ã¿ãGitHub ã§å
¬éããŠãã ç¹ã§ãã ç¹å®ã®æ»æã³ãŒãã ããèŠãã®ã§ã¯ãªããæ»æã«å¿
èŠãª primitive ã behavior ãèŠãã ãããŠããã®ããžãã¯ããªãŒãã³ã«ããããšã§ãã³ãã¥ããã£å
šäœã®é²åŸ¡åãåºäžãããã ããã¯ãçŸä»£ã®ã»ãã¥ãªãã£éçšã«ãããŠãšãŠãéèŠãªèãæ¹ã§ãã æ»æè
ã¯ã³ãŒãã®èŠãç®ãå€ããããŸãã ããããrootæš©éãåãããã«å¿
èŠãªè¡åã®æµãã¯ãå®å
šã«ã¯é ãã«ããã§ãã Elastic Security ã¯ããã®æµããããŒã¿ããèŠã€ããããã®ãã©ãããã©ãŒã ã§ãã ãããŠããã®æ€ç¥ããžãã¯ã ãªãŒãã³ã«ãéæã«ãã³ãã¥ããã£ãšå
±ã«é²åãããŠãã ã®ããElastic ã®å€§ããªåŒ·ã¿ã§ãã åèãªã³ã¯ Elastic Security Labs åæããã°: Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild Elastic ã®æ€ç¥ã«ãŒã«ãªããžããª: elastic/detection-rules (GitHub) CISA Known Exploited Vulnerabilities Catalog: CISA KEV ãã®èšäºã¯ãElastic Security Labs ãå
¬éããè±èªããã°ãCopy Fail and DirtyFrag: Linux Page Cache Bugs in the Wildããããšã«ãæ¥æ¬ã®Elasticå©çšè
åãã«æŽçã»è£è¶³ãããã®ã§ãã The post Copy Fail / DirtyFrag ãæ€ç¥ããïŒLinux ã«ãŒãã«ã® page cache æ»æãš5ã€ã®æ€ç¥ã«ãŒã« first appeared on Elastic Portal .
åç»
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã







