High SEVERITY — Vulnerability

Dirty Pipe: Linux kernel write-privilege vulnerability (CVE-2022-0847)

A bug in the pipe mechanism allows overwriting of read-only files and can lead to root privileges.

Platform
Ubuntu Server
Version
22.04 LTS / Jammy Jellyfish
CVE Record
CVE-2022-0847
CVSS Score
7.8/10
Advisory
USN-5317-1
Published
08 March 2022
Views
5
Primary source: Review the official advisory at ubuntu.com Kaynağa Git

Summary

The Dirty Pipe vulnerability in 5.8+ kernels allowed unauthorized writes to the page cache. Public exploit code enabled any local user to gain root privileges.

Solution

Patched kernel packages were released in USN-5317-1. 20.04 systems using the HWE kernel were also affected and were updated in the same round.

Ubuntu Server — Related Advisories

VIEW ALL →