Dirty Pipe: Linux kernel write-privilege vulnerability (CVE-2022-0847)
A bug in the pipe mechanism allows overwriting of read-only files and can lead to root privileges.
A bug in the pipe mechanism allows overwriting of read-only files and can lead to root privileges.
The Dirty Pipe vulnerability in 5.8+ kernels allowed unauthorized writes to the page cache. Public exploit code enabled any local user to gain root privileges.
Patched kernel packages were released in USN-5317-1. 20.04 systems using the HWE kernel were also affected and were updated in the same round.
The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
Bulk security patches for the OpenSSL, curl, sudo and systemd packages were published this month.