Files
pokemon_pinball_wiki/copy-fail-assessment.md
2026-07-06 20:06:06 -05:00

4.0 KiB

Copy Fail Assessment

Short Answer

Based on the extracted rootfs, this kernel should be treated as vulnerable to Copy Fail / CVE-2026-31431 unless Stern or Raspberry Pi backported the fix into this exact 6.6.28-v8 kernel build out-of-band.

The available local evidence points vulnerable:

  • Kernel module tree is /lib/modules/6.6.28-v8.
  • algif_aead.ko.xz is present as a loadable module.
  • authencesn.ko.xz is present as a loadable module.
  • modules.dep wires both into the normal module dependency map.
  • algif_aead module metadata describes it as AEAD kernel crypto API user space interface.
  • authencesn module metadata describes it as AEAD wrapper for IPsec with extended sequence numbers.
  • No /etc/modprobe.d mitigation was present in the extracted rootfs.
  • No local marker for the upstream fix commit a664bf3d603d was found in the rootfs.

Why This Is In Scope

Copy Fail is a Linux kernel local privilege escalation in the crypto authencesn / AF_ALG path. Public guidance says the primary fix is a kernel containing mainline commit a664bf3d603d, with temporary mitigation by disabling algif_aead.

This rootfs carries the relevant affected modules:

/lib/modules/6.6.28-v8/kernel/crypto/algif_aead.ko.xz
/lib/modules/6.6.28-v8/kernel/crypto/authenc.ko.xz
/lib/modules/6.6.28-v8/kernel/crypto/authencesn.ko.xz

The module vermagic for both checked modules is:

6.6.28-v8 SMP preempt mod_unload modversions aarch64

6.6.28 predates the public 2026 Copy Fail fix window. Without source or a vendor changelog proving a backport, assume affected.

Local Exploitability Notes

The extracted permissions do not show the usual broad setuid surface:

  • No setuid files were found with find . -xdev -type f -perm -4000.
  • No setgid files were found with find . -xdev -type f -perm -2000.
  • /bin/su exists only as a non-setuid symlink to busybox.

That means the stock public exploit path that targets a setuid binary such as /usr/bin/su likely will not work unchanged on this image.

However, the kernel exposure should still matter for threat modeling:

  • If an attacker obtains unprivileged local code execution and can load or trigger algif_aead, the vulnerable kernel primitive may be reachable.
  • The system appears to run the main game and monitors as root from init. A page-cache corruption primitive may still be adaptable against root-executed readable binaries or scripts, even without classic setuid helpers.
  • Embedded deployments often have fewer unprivileged accounts, which lowers exposure, but a network/app compromise that lands in a non-root context could still use this as a step-up if the primitive is reachable.

Mitigation Options To Test On Hardware

Preferred:

  1. Boot a kernel containing the Copy Fail fix or a vendor backport of mainline commit a664bf3d603d.
  2. Confirm the running kernel version and vendor build date on the machine.
  3. Confirm whether algif_aead can be autoloaded from an unprivileged process.

Temporary mitigation if patching is not yet possible:

install algif_aead /bin/false

Place that in a modprobe policy file if the deployed image honors /etc/modprobe.d, then unload algif_aead if already loaded. This rootfs did not include an existing /etc/modprobe.d directory, so test the exact Buildroot/kmod behavior on hardware before relying on it.

Also consider a seccomp rule blocking AF_ALG socket creation for any untrusted workload, though this image does not currently look like a container or multi-user host.

Commands Used For Static Check

rg -n "algif_aead|authencesn|AF_ALG|a664bf3d603d|disable-algif" .
find lib/modules/6.6.28-v8 -path '*algif_aead*' -o -path '*authenc*' -o -path '*authencesn*'
xz -dc lib/modules/6.6.28-v8/kernel/crypto/algif_aead.ko.xz | strings | rg -n "vermagic|depends|description|AF_ALG|aead|6\\.6"
xz -dc lib/modules/6.6.28-v8/kernel/crypto/authencesn.ko.xz | strings | rg -n "vermagic|depends|description|authenc|authencesn|6\\.6"
find . -xdev -type f -perm -4000 -exec ls -l {} \;
find . -xdev -type f -perm -2000 -exec ls -l {} \;