¡¾·ì϶¹«¸æ¡¿Linux ÄÚºË Copy Fail ±¾µØÌáȨ·ì϶(CVE-2026-31431)

°ä²¼¹¦·ò 2026-04-30

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Linux ÄÚºË Copy Fail ±¾µØÌáȨ·ì϶

CVE   ID

CVE-2026-31431

·ì϶ÀàÐÍ

ȨÏÞÌáÉý

·¢ÏÖ¹¦·ò

2026-4-30

·ì϶ÆÀ·Ö

7.8

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

±¾µØ

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


LinuxÄÚºËÊDzÙ×÷ϵͳÖ÷Ìâ×é¼þ£¬£¬£¬£¬£¬£¬ £¬ÕƹÜÖÎÀíÓ²¼þ×ÊÔ´²¢ÎªÀûÓÃÌṩͳһ½Ó¿Ú¡£¡£¡£¡£¡£¡£ÆäÖØÒªÖ°ÄÜÔ̺¬¹ý³Ìµ÷¶È¡¢ÄÚ´æÖÎÀí¡¢Îļþϵͳ¡¢ÍøÂçºÍ̸ջ¼°É豸Çý¶¯ÖÎÀí¡£¡£¡£¡£¡£¡£Linux kernelÓµÓпªÔ´¡¢¸ß»úÄÜ¡¢²»±äÐÔÇ¿ºÍ¿ÉÀ©´óÐԺõÄÌØµã£¬£¬£¬£¬£¬£¬ £¬¿í·ºÀûÓÃÓÚ·þÎñÆ÷¡¢ÔÆÍÆË㡢ǶÈëʽϵͳ¼°ÈÝÆ÷ƽ̨¡£¡£¡£¡£¡£¡£


2026Äê4ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬ £¬8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Linux ÄÚºË Copy Fail ±¾µØÌáȨ·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ¼ÓÃÜ×ÓϵͳauthencesnÄ£°åÔÚ´¦ÖÃAF_ALGÓësplice()ʱδÕýÈ·¸ôÀëpage cacheÒýÓ㬣¬£¬£¬£¬£¬ £¬µ¼ÖÂÈÏÖ¤±êǩδ¸´Ôì¶øÖ±½Ó¹ØÁªÔ­Ê¼ÄÚ´æÒ³¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓøÃȱµã¶ÔËÁÒâ¿É¶ÁÎļþµÄpage cacheÖ´ÐпɿØÐ´È룬£¬£¬£¬£¬£¬ £¬½ø¶ø´Û¸Äsetuid·¨Ê½ÄÚ´æÓ³Ïñ£¬£¬£¬£¬£¬£¬ £¬ÊµÏÖȨÏÞÌáÉýÖÁroot¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÀûÓÃÎÞÐ辺̬ǰÌᣬ£¬£¬£¬£¬£¬ £¬ÀûÓÃÃż÷µÍÇÒÒñ±ÎÐÔÇ¿£¬£¬£¬£¬£¬£¬ £¬Åú¸Ä²»»áÂäÅÌ£¬£¬£¬£¬£¬£¬ £¬ÄÑÒÔ±»ÆëÈ«ÐÔ¼ì²â·¢ÏÖ¡£¡£¡£¡£¡£¡£Í¬Ê±Ó°ÏìÈÝÆ÷»·¾³£¬£¬£¬£¬£¬£¬ £¬¿ÉÄܵ¼ÖÂÈÝÆ÷ÌÓÒÝÓëºáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬ £¬½ø¶øÒý·¢Êý¾Ýй¶¡¢ÏµÍ³Ê§¿ØµÈ°²È«·çÏÕ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


72548b093ee3 <= commit < a664bf3d603d£¬£¬£¬£¬£¬£¬ £¬¸Ã·ì϶ӰÏìÔ̺¬ÉÏÊöcommitÇø¼äµÄLinuxÄں˰汾£¬£¬£¬£¬£¬£¬ £¬Éæ¼°2017ÄêÖÁ2026Äê¼äÖ÷Á÷Linux¿¯Ðаæ£¬£¬£¬£¬£¬£¬ £¬Ô̺¬µ«²»ÏÞÓÚ»ùÓÚDebianϵµÄUbuntu£¨18.04¡¢20.04¡¢22.04¡¢24.04£©ÓëDebian£¨10¡¢11¡¢12£©£¬£¬£¬£¬£¬£¬ £¬»ùÓÚRed HatϵµÄRHEL£¨7¡¢8¡¢9¡¢10£©¼°ÆäÑÜÉú°æ±¾Rocky Linux¡¢AlmaLinux£¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°SUSE Linux Enterprise£¨12¡¢15£©ºÍopenSUSE£¬£¬£¬£¬£¬£¬ £¬Í¬Ê±Ô̺¬Amazon Linux£¨2¡¢2023£©µÈÔÆ³§ÉÌ¿¯Ðа档¡£¡£¡£¡£¡£ÓÉÓÚ·ì϶´æÔÚÓÚLinuxÄÚºËͨÓÃ×é¼þÖУ¬£¬£¬£¬£¬£¬ £¬ÏÖʵӰÏìÁìÓòÈ¡¾öÓÚ¿¯ÐаæËù¼¯³ÉµÄÄں˰汾¼°ÆäbackportÇé¿ö¡£¡£¡£¡£¡£¡£


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬£¬£¬£¬£¬£¬ £¬ÒÔ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£

Linux Kernel 6.18 >= 6.18.22

https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8

Linux Kernel 6.19 >= 6.19.12

https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237

Linux Kernel 7.0 >= 7.0

https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5

¾É°æ±¾½¨¸´½¨Ò飺

¶ÔÓÚÁÙʱÎÞ·¨Éý¼¶ÖÁÉÏÊö°æ±¾µÄϵͳ£¬£¬£¬£¬£¬£¬ £¬½¨ÒéÊÖ¶¯»ØÒÆÖ²¹Ù·½²¹¶¡£¡£¡£¡£¡£¡£º

ÀûÓàCommit£ºa664bf3d603d

½¨¸´ÄÚÈÝ£ºRevert to operating out-of-place£¨»ØÍËΪ·ÇÔ­µØ²Ù×÷ģʽ£©


3.2 Ò»Ê±´ëÊ©


# echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf

# rmmod algif_aead


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ £¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬£¬ £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£

? ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬£¬ £¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬£¬ £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬£¬ £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬£¬ £¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£

? Ê¹ÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬£¬ £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£

? ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬£¬ £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£

? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2026/04/29/23/

https://xint.io/blog/copy-fail-linux-distributions

https://github.com/theori-io/copy-fail-CVE-2026-31431