å æ¥ã®ãã³ããŒãã§ãŒã«ãéšåã§å šäžçã®LinuxãµãŒããŒãéãäžãã£ãã°ããã§ããããããæ°æ¥åŸã«åãLinuxã«ãŒãã«ãããŸãæ°ãããŒããã€ãçºèŠãããŸããããã®åããããŒãã£ãã©ã°(Dirty Flag)ãã2017幎1æã«å ¥ã£ãæå·åŠçé¢é£ã®ã³ãŒã倿Žãã9幎éãŸã£ããèŠçŽãããªããŸãŸæ·±å»ãªè匱æ§ãšããŠåçºèŠãããã®ã§ããð±
ãããŠä»åã¯ååãšæ±ºå®çã«éãç¹ããããŸããããã¯ãã§ã«ãIn the Wild(å®äžçã§ã®æ»æ)ãã芳枬ãããŠãããšããããšãMicrosoftã5æ8æ¥ã«å ¬åŒããã°ã§äŸµå®³äºäŸãå ¬éããæ»æã³ãŒãã¯GitHubã§èª°ã§ãå ¥æã§ããç¶æ ã§ããããªããå¯ãŠããéã«ãæ»æè ã¯ç¢ºå®ã«åããŠããŸããä»å€äžã®å¯Ÿçã§ãå®å¿ããŠç ããææ¥ãåãæ»ããŸããããðŽâš
ä¿®æ£ããããè¡ãæž¡ãåã«æ»æè ãæªçšã§ããç¶æ ã®è匱æ§ã®ããšãä»åã®ããŒãã£ãã©ã°ã¯ãŸãã«ãã®å žåã§ã5æ7æ¥ã«ç¬¬äžè ãä¿®æ£ããããéè§£æããŠæ»æã³ãŒããå ¬éããŠããŸããé²åŸ¡ããå ã«æ»æããŠããŠãäžçã«åºåã£ãŠããŸããŸãããâ¡
Linuxã«ã¯éå»ã«ããæ±ãããååãæã€è匱æ§ãããã€ããããŸããã2022幎ã®ããŒãã£ãã€ããå é±ã®ã³ããŒãã§ãŒã«ããããŠä»é±ã®ããŒãã£ãã©ã°ããããã¯ãã¹ãŠããŒãžãã£ãã·ã¥ç¬(Page Cache Poisoning)ãšåŒã°ããè匱æ§ã¯ã©ã¹ã«å±ããŠããŸãã
Linuxã¯ãã¡ã€ã«ãéããšäžèº«ãäžæçã«ã¡ã¢ãªã«çœ®ããŸãããããããŒãžãã£ãã·ã¥ããã®ãã£ãã·ã¥ãæ»æè ãå€åŽããæžãæããŠããŸãã®ãããã®ã¯ã©ã¹ã®åºæ¬æ§é ã§ãã
ããŒãã£ãã©ã°ã®æãããã¯ãæžãæãã§ããç¯å²ãããŒãã£ãã€ãããå§åçã«åºãç¹ããWrite-What-Whereãã€ãŸãã©ãã«äœã§ãæžãããšãããæ»æè ã«ãšã£ãŠæé«ã®ç²ç©ãšãªãèªç±åºŠãæã£ãŠããŸããð¯
ããŒãã£ãã©ã°ã¯2ã€ã®è匱æ§ããã§ãŒã³ããã2段åã®æ»æã§ãã
XFRM/ESPåŽã¯ã³ã³ããå ãªã©ã§äœ¿ãåå空éã®ç¹æš©ãå¿ èŠã§ãããRxRPCåŽã¯ç¹æš©ãªãã§æç«ããŸããçµã¿åãããããšã§ãäºãã®åŒ±ç¹ãè£å®ããå®å šãªæ»æãã§ãŒã³ãæç«ãããâãŸãã«èžè¡çãšãèšããèšèšãªã®ã§ããð
XFRM/ESPã®æ¬è³ªçãªãã°ã¯ãmsg_splice_pagesãšãããªãã·ã§ã³ã§ãã€ãããçŽæ¥ããŒãžãæž¡ãéã«ããã®ããŒãžããå ±æããšããŒã¯ãå¿ãããšãããã®ãæ¬æ¥ã³ããŒãã¹ããšãããå ±æã®ãŸãŸæžãæããŠããŸããããæã¡äž»ã®ããŒã¿ãç Žå£ãããŸããä¿®æ£ãããã§ã¯ãå ±æããŒãžãªãå®å šãªçµè·¯ã«ãã©ãŒã«ããã¯ããããšããããžãã¯ã远å ãããŸããã
ãæ±ºå®è«ç(Deterministic)ããšã¯ãã¬ãŒã¹ã³ã³ãã£ã·ã§ã³ãå¿ èŠãšããæ¡ä»¶ãæãã°ç¢ºå®ã«æç«ãããšããæå³ã§ããããã倱æããŠããµãŒããŒãèœã¡ãªããããæ»æè ã¯äœåºŠã§ã詊è¡ã§ããŸããèŠåå¡ãèŠãŠããåã§å ã ãšé庫ãéããããã®ã«ãèŠåå¡ã«ã¯äœãèŠããªãâãããªç¶æ ãðš
CVSSã¹ã³ã¢ã¯7.8(High)ãã¹ã³ãŒã倿Žãããšããã®ãç¹ã«äžç©ã§ãããã¯ã³ã³ããå ã§æ»æãå§ãŸã£ãŠããã¹ãåŽã«ãŸã§åœ±é¿ãåã¶å¯èœæ§ããããšããæå³ã§ããã¯ã©ãŠãäºæ¥è ã«ãšã£ãŠã¯æªå€¢ã®ã·ããªãªãšèšããã§ãããã
çŸä»£ã®ã¯ã©ãŠãã¯ã»ãŒãã¹ãŠã³ã³ããæè¡ã§åããŠããŸããDockerãKubernetesãAWS ECSãGoogle Cloud RunâŠãã³ã³ããã®å®å šæ§ã¯ãç®±ãç Žãããªãåæãã§æãç«ã£ãŠããŸãããããŒãã£ãã©ã°ã¯ãã®ç®±ãç Žãèœåãæã¡ãŸãã
Canonicalã®å ¬åŒã¢ããã€ã¶ãªã¯æç¢ºã«ããèŠåããŠããŸããããµãŒãããŒãã£ã®ã¯ãŒã¯ããŒããå®è¡ããã³ã³ããç°å¢ã§ã¯ã³ã³ããè±åºãåŒãèµ·ããå¯èœæ§ããããããã«ãããã³ãç°å¢ãã€ãŸãè€æ°ã®é¡§å®¢ããµãŒããŒãå ±æããã¯ã©ãŠããç¹ã«å±éºã§ãCIã©ã³ããŒããµãŒããŒã¬ã¹åºç€ãæå€§ã®æžå¿µãã€ã³ãã§ããGitHub Actionsã®ã»ã«ããã¹ãåã©ã³ããŒã䜿ã£ãŠããçµç¹ã¯ä»ããç¹æ€ããð ïž
UbuntuãRed HatãSUSEãªã©ã®äž»èŠãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯5æ8æ¥ä»¥éãé æ¬¡ããããå ¬éããŠããŸããUbuntuãªã以äžã®ã³ãã³ãã§å¯Ÿå¿å¯èœã
sudo apt update && sudo apt upgrade -y && sudo reboot
ããããããåœãŠãããªãå Žåã¯ãmodprobeã®èšå®ãã¡ã€ã«ã1ã€äœãã ãã§æ»æé¢ãå¡ããŸããå°éãã¹ãã¯esp4 / esp6 / rxrpcã®3ã¢ãžã¥ãŒã«ããã ãIPSec VPNã䜿ã£ãŠããç°å¢ã§ã¯æ¥å圱é¿ãåºãããèŠæ³šæã
æ»æã®éäžã§æ±æãããããŒãžãã£ãã·ã¥ãã¡ã¢ãªã«æ®ã£ãŠããå¯èœæ§ããããããäžæŠå šæ¶ãããã®ãdrop_cachesã³ãã³ããæ»æã®çè·¡ãæã¡åãç®çã§å®è¡ããŸãã
RxRPCã®CVE-2026-43500ã«ã€ããŠã¯5æ8æ¥æç¹ã§ããããæªå ¬éã®ãããmodprobeå°éãäºå®äžå¯äžã®é²åŸ¡çã§ããã³ã³ããéçšè ã¯ãäžèŠãªç¹æš©ã³ã³ããã®åæ¢ãšã±ã€ãããªãã£ã®å確èªãå¿ããã«ãð
ããããè匱æ§ã«å·éã«å¯Ÿå¿ã§ããåãã€ããã«ã¯ãä»ãçŒãåã§ã¯ãªãäœç³»çãªç¥èãäžå¯æ¬ ã§ããä»åã®ãããªäºæ¡ããèªåããšããšããŠèªã¿è§£ããåãé€ãããAmazonã§æã«å ¥ãå³éžæžç±ã玹ä»ããŸããð
SKB(ãœã±ãããããã¡)ãããŒãžãã£ãã·ã¥ãšãã£ãæ¬èšäºã®ããŒã¯ãŒãããã®ãŸãŸç»å Žããã¬ãã«ã®ç¥èãåŸãããå®çªæžãã«ãŒãã«ã®å éšãçè§£ã§ããã°ãCVEã®è§£èª¬èšäºãèªãã§ãããªããã®ãã°ãèŽåœçãªã®ãããè ã«èœã¡ãããã«ãªããŸãã
ãããé©çšãmodprobeãsystemdããã°èª¿æ»âä»åã®å¯Ÿçã§å¿ èŠã ã£ãå®åç¥èãç¶²çŸ çã«åŠã¹ãäžåãã3è¡ã®ã³ãã³ãã§èªåã®ãµãŒããŒãå®ããæèŠã身ã«ã€ãããæ¹ã«æé©ã§ãã
ãããã¡ãªãŒããŒãããŒãUse-After-Freeãæš©éææ Œãªã©ããŒããã€ã®æ»æãã¯ããã¯ãæ»æè èŠç¹ã§è§£èª¬ãé²åŸ¡ããããã«ã¯ãŸãæ»æãçè§£ããããšããçéã¢ãããŒãã§åŠã¹ãŸãã
ã³ã³ããè±åºããã«ãããã³ããCIã©ã³ããŒãšãã£ãæ¬èšäºã®ããŒã¯ãŒãããã¹ãŠã«ããŒãããŠããå®è·µæžãKubernetesæä»£ã®ã»ãã¥ãªãã£èšèšãåŠã¹ãŸãã
ãæ»æã¯ããå§ãŸã£ãŠããããšããç¶æ³ã§äœãèŠãã¹ããããã°ã»ãã±ããã»ã¡ã¢ãªã®ã©ãã«çè·¡ãæ®ãããä»åã®ãããªæäºã«å·éã«åããéçšè ã«ãªãããã®äžåã§ãã
ãµãŒããŒã»ã©åè¿«ã¯ããŸããããIPSec VPNã䜿ã£ãŠããæ¹ããéçºçšã«DockerãåãããŠããæ¹ã¯åœ±é¿ãåãåŸãŸãããã£ã¹ããªãã¥ãŒã·ã§ã³ã®èªåæŽæ°ãæå¹ã«ããåèµ·åãå¿ããã«è¡ã£ãŠãã ããã
AWS LambdaãCloud RunãECSãªã©äž»èŠãªãããŒãžããµãŒãã¹ã¯ã¯ã©ãŠãäºæ¥è åŽããã¹ãã«ãŒãã«ããããããŸãããã ãEC2ãGCEã®ãããªèªåã§OSã管çããç°å¢ã¯ãŠãŒã¶ãŒè²¬ä»»ã§ããå ±æè²¬ä»»ã¢ãã«ãå確èªããŸãããã
esp4/esp6ãæ¢ãããšIPSec VPNã¯æ©èœããªããªããŸããVPNå©çšãå¿ é ãªãå°éã§ã¯ãªãã«ãŒãã«ãããé©çšãæ¬åœã§ããå¿æ¥åŠçœ®ãšæ¬çªéçšã¯åããŠèããŸãããã
æå·åŠçãšããå°å³ãªå®è£ 倿ŽãšããŠå ¥ã£ããããã³ãŒãã¬ãã¥ãŒãèªåè§£æãèŠèœãšããŠããŸãããOSSã®ãå€ãã®ç®ã§èŠãããŠããããå®å šããšããåæã厩ããå žåäŸã§ãä»åŸãåçš®ã®çºèŠãç¶ããšäºæž¬ãããŠããŸãã
ãŸãã¯Linuxã®åºç€(ãã¡ã€ã«ã·ã¹ãã ãããã»ã¹ãæš©éã¢ãã«)ãåºããããšãæçã«ãŒãããã®äžã§ãæ»æè ãã©ãèãããããåŠã¶ãšããã¥ãŒã¹ã§æµããCVEã®æå³ãã¹ããšå ¥ã£ãŠããããã«ãªããŸããäžèšã®æžç±â â¡ããå§ããã®ãããããã§ããð
ããŒãã£ãã©ã°ã¯Linuxã«ãŒãã«ã«9幎æœäŒããããŒãžãã£ãã·ã¥ç¬æ®ºã®æ°ã¯ã©ã¹è匱æ§ã§ãããCVE-2026-43284ãšCVE-2026-43500ããã§ãŒã³ããŠã«ãŒãæš©éãå¥ªãæ±ºå®è«åãã°ã§ããMicrosoftã5æ8æ¥ã«In the Wildæ»æã確èªããæ»æã³ãŒãã¯GitHubã§å ¬éæžã¿ãã³ã³ããè±åºãåŒãèµ·ããå¯èœæ§ããããCIã©ã³ããŒããµãŒããŒã¬ã¹åºç€ã«æå€§çŽã®è åšãšãªã£ãŠããŸãã
ããªããä»ããããã¹ãããšã¯2æãã«ãŒãã«ããããåœãŠãããesp4/esp6/rxrpcã®3ã¢ãžã¥ãŒã«ãå°éããããã·ã³ãã«ãªã®ã«å¹æã¯çµ¶å€§ã§ãããããŠé·æçã«ã¯ãããããäºæ¡ãèªåã®èšèã§èªã¿è§£ããåããæžç±ã§ãã£ããè²ãŠãŠãããŸããããð
ä»å€ã®3è¡ã®ã³ãã³ããšãæ¬æ£ã«äžŠã¶äžåããææ¥ããã®ããªãã®ãã£ãªã¢ãšçµç¹ãå®ã£ãŠãããŸããå®å¿ããŠããŸããªããšèšããæ¯æ¥ã®ããã«ãä»ããåããŸããã!ð§ð¡ïž
â ïž Windowsã»ãã¥ãªã…
ð§ çªç¶ã®æçš¿ã«ãã¡ã³éšç¶ïŒã©…
ð§© ããºã«ãè§£ãå¿«æãã³ãŒãã§…
âš ããã°ã©ã ã®åäœã軜ããã…
ð ãµãŒããŒãµã€ãéçºã®äžçãž…
âš é¢åãªWebäœæ¥ãèªååã…