PT-2022-1364 · Linux+11 · Linux Kernel+11
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.8 through 5.16.10
Linux kernel versions 5.15 through 5.15.24
Linux kernel versions 5.10 through 5.10.101
Description
An issue exists in the Linux kernel where the
flags member of the new pipe buffer structure is not properly initialized within the copy page to iter pipe() and push pipe() functions. This lack of initialization can lead to the presence of stale values, allowing an unprivileged local user to overwrite data in the page cache of arbitrary read-only files. This flaw can be exploited to escalate privileges, modify sensitive files such as /etc/passwd, inject code from unprivileged processes into privileged ones, or create unauthorized root-level access, such as adding SSH keys to the root account. The issue also affects Android devices utilizing the vulnerable kernel versions, where it can be leveraged by malicious applications to gain elevated permissions.Recommendations
Update Linux kernel to version 5.16.11 or newer.
Update Linux kernel to version 5.15.25 or newer.
Update Linux kernel to version 5.10.102 or newer.
Exploit
Fix
DoS
LPE
RCE
Improper Initialization
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Zvirt Node