Today is Friday, and as every Friday, like clockwork, I will turn up the "mess with the crawlers" knob. Today is also the first of May, where we celebrate not one, but two birthdays: my Wife's and mine.
In good Hobbit tradition, on birthdays, we do not get presents. We give persents. On this beautiful day, here's my present to you all: some of the crawlers will happily honor Content-Disposition: attachment; filename="/lib/libc.so.6" and the like. Yes, they'll try to save the file to an absolute path of your choosing.
Now, they usually don't run as root, but there's so many other ways to exploit this vulnerability! Like, if a crawler was a bash script using curl without -q, ~/.curlrc would present a few fun opportunities.
Combine that with other exploits, such as copy.fail, and remember that many of the systems used for crawling are ancient and contain multitudes of such vulnerabilities.
Happy Friday!
@kemona_halftau for reasons™ (dotnet isn’t bootstrappable so it’s not packaged in guix) I’m running dotnet stuff on a server that doesn’t often reboot so stuff cluttering up /tmp is annoying. as a workaround I’ll wrap it in a user/mount namespace and give it its own private /tmp (which of course would break anything that relies on a shared /tmp if I use it for dotnet run but I don’t think OpenDiepix5 does that anyway):
/* SPDX-License-Identifier: GPL-3.0-or-later */
#define _GNU_SOURCE
#include <stdio.h>
#include <unistd.h>
#include <sched.h>
#include <errno.h>
#include <sys/mount.h>
void write_proc_maps(uid_t uid, gid_t gid) {
FILE *fp;
fp = fopen("/proc/self/setgroups", "w");
if (fp) {
fprintf(fp, "deny");
fclose(fp);
} else perror("fopen setgroups");
fp = fopen("/proc/self/uid_map", "w");
if (fp) {
fprintf(fp, "%d %d 1", uid, uid);
fclose(fp);
} else perror("fopen uid_map");
fp = fopen("/proc/self/gid_map", "w");
if (fp) {
fprintf(fp, "%d %d 1", gid, gid);
fclose(fp);
} else perror("fopen gid_map");
}
int main(int argc, char **argv) {
if (argc < 2) {
fprintf(stderr, "Error: Not enough arguments: %d.\n", argc);
return 1;
}
uid_t uid = geteuid();
gid_t gid = getegid();
if (unshare(CLONE_NEWUSER | CLONE_NEWNS)) {
perror("unshare");
return errno;
}
write_proc_maps(uid, gid);
if (mount("none", "/tmp", "tmpfs", 0, NULL)) {
perror("mount");
return errno;
}
execvp(argv[1], &argv[1]);
perror("execvp");
return errno;
}
OpenWrt is still vulnerable to copyfail and doesn’t compile algif_aead as a module or include BPF-LSM support
Edit: it does, in fact, compile algif_aead as a module (kmod-crypto-user)
If you are as annoyed as me about the fancy CVE-2026-31431 website not actually mentioning what Kernel versions to update to (only mentioning the commit rev), I translated this for you by looking through the releases manually and checking if they contain the fix.
The following upstream kernel tags contain the fix:
6.6.137+
6.12.85+
6.18.22+
6.19.12+
7.0+
But of course your distro might also apply the patches on any other version, and they will hopefully provide that information.
Edit: added 6.6/6.12 versions