天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-107785 Crux Agent WireGuard 预共享密钥长度校验缺失漏洞

影响隧道重启失败,或在特定配置下隧道流量可被解密

MEDIUM
暂无 CVSS 评分
AI 研判

Crux Agent 1.9.0 至 2.0.3 之前版本将完整的 SKA 双位置密钥直接用作 WireGuard 预共享密钥。当对等会话协商使用 SHA-512 时,生成的密钥为 64 字节,而 WireGuard 要求 32 字节,代理未校验该长度即尝试写入配置并更新隧道。

影响范围

Crux Agent

Crux Agent 1.9.0 起至 2.0.3 之前的版本。

漏洞详情

漏洞源于密钥长度校验缺失:SHA-512 协商产生 64 字节密钥,超出 WireGuard 所需的 32 字节,代理仍调用 wg set 并写入配置文件,导致更新失败、隧道重启时无法启动。在未启用 Enforce SKA Use 且从未成功协商 32 字节密钥的组织中,隧道可能完全不设置预共享密钥,使具备量子计算能力的攻击者可在截获流量后解密。

利用条件与风险

利用前提是攻击者能截获并存储对等节点流量,并拥有或未来拥有密码学相关量子计算机;实战中更直接的后果是隧道重启失败导致服务中断。

修复建议

升级至 Crux Agent 2.0.3 或更高版本;临时可启用 Enforce SKA Use 设置并确保协商使用 32 字节密钥,同时监控隧道状态。

原始情报

Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted.

For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the “Enforce SKA Use” setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer’s traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.