Forum Moderators: bakedjake

Message Too Old, No Replies

Linux Dirty Pipe Vulnerability Fixed in 5.16.11, 5.15.25 and 5.10.102

         

engine

11:45 am on Mar 8, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Details of the Linux Dirty Pipe vulnerability were released following the fix being released for Linux 5.16.11, 5.15.25 and 5.10.102. The vulnerability was in the "Linux kernel since 5.8 which allows overwriting data in arbitrary read-only files. This leads to privilege escalation because unprivileged processes can inject code into root processes."

You can find full details here [dirtypipe.cm4all.com...]

Dimitri

2:38 pm on Mar 8, 2022 (gmt 0)

WebmasterWorld Senior Member 5+ Year Member Top Contributors Of The Month



Peace first,

Similar to “Dirty COW”, and I like the "easier to exploit". I wonder since how long hackers are aware of it, and if there were exploits in real life.

engine

5:10 pm on Mar 8, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



It was amazing how long Dirty Cow was around for before being patched. [webmasterworld.com...]

I'd like to think everyone has patched their systems to the relevant updates for Dirty Pipe. If you haven't, you'd better get on with it now that the exploit was published.