Security Leftovers

-
Security updates for Monday
Security updates have been issued by Debian (chromium, containerd, cyrus-sasl2, expat, firefox-esr, freecad, kernel, and tiff), Fedora (seamonkey, swtpm, and webkit2gtk3), Mageia (docker-containerd, firefox, flac, libtiff, libxml2, and mc), openSUSE (containerd, expat, flatpak, gnutls, go1.16, go1.17, libeconf, shadow and util-linux, mariadb, nodejs14, perl-App-cpanminus, vim, wireshark, wpa_supplicant, and zsh), SUSE (containerd, expat, flatpak, gnutls, go1.16, go1.17, java-11-openjdk, kernel-firmware, libeconf, shadow and util-linux, libxml2, mariadb, nodejs14, python-Twisted, vim, wireshark, wpa_supplicant, and zsh), and Ubuntu (firefox, openjdk-lts, openjdk-17, and php8.0).
-
The "dirty pipe" vulnerability
Max Kellermann has disclosed a disconcerting kernel vulnerability...
-
The Dirty Pipe Vulnerability
It all started a year ago with a support ticket about corrupt files. A customer complained that the access logs they downloaded could not be decompressed. And indeed, there was a corrupt log file on one of the log servers; it could be decompressed, but gzip reported a CRC error. I could not explain why it was corrupt, but I assumed the nightly split process had crashed and left a corrupt file behind. I fixed the file’s CRC manually, closed the ticket, and soon forgot about the problem.
Months later, this happened again and yet again. Every time, the file’s contents looked correct, only the CRC at the end of the file was wrong. Now, with several corrupt files, I was able to dig deeper and found a surprising kind of corruption. A pattern emerged.
-

- Login or register to post comments
Printer-friendly version- 6908 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

LF fluff
A Summary of Census II: Open Source Software Application Libraries the World Depends On
'Dirty Pipe' Linux vulnerability discovered
'Dirty Pipe' Linux vulnerability discovered | ZDNet
New Linux bug gives root on all major distros, exploit released
New Linux bug gives root on all major distros, exploit released [Ed: Microsoft booster Lawrence Abrams makes it sound a lot more severe than it actually is]
Linux vulnerability allows an attacker to overwrite data
'Dirty Pipe' Linux vulnerability allows an attacker to overwrite data - SiliconANGLE
Serious 'Dirty Pipe' Bug Patched in Linux Kernel | Decipher
Linux has been bitten by its most high-severity vulnerability in years | Ars Technica
Linux distributions patch kernel privilege escalation flaw • The Register
This major Linux security vulnerability has been fixed, so patch now | TechRadar
Researchers Warn of Linux Kernel 'Dirty Pipe' Arbitrary File Overwrite Vulnerability
SUSE's statement, moments ago
SUSE statement on "Dirty Pipe" attack | SUSE Communities
False headline
Apparently, the vulnerability in the Linux kernel has been around since version 5.8, which was released in August 2020. It’s tracked as CVE-2022-0847. It allows overwriting data in arbitrary read-only files, which means attackers can escalate privileges, giving them access they shouldn’t have. Once privileges are escalated, they can do all sorts of things on a system.
Creating an SSH key is just one of many actions an attacker can take when exploiting the vulnerability. One can hijack a SUID binary to create a root shell, and another can allow untrusted users to overwrite data in read-only files. These are severe attacks that could do all sorts of damage to a system.
“It’s about as severe as it gets for a local kernel vulnerability,” Brad Spengler, president of Open Source Security, wrote in an email to Ars Technica. “Just like Dirty Cow, there’s essentially no way to mitigate it, and it involves core Linux kernel functionality.”
Slashdot FUD factory
Linux Has Been Bitten By Its Most High-Severity Vulnerability in Years [Ed: Slashdot promotes the most misleading story]
Liliputing now
Lilbits: Archiving Android apps, postmarketOS for the F(x)tec Pro1, and the Dirty Pipe Linux vulnerability - Liliputing
Exaggeration
Easily exploitable Linux bug gives root access to attackers (CVE-2022-0847) [Ed: Well, attackers that already have full machine access]
SJVN FUD
Dirty Pipeline Is an Awful Linux Mess [Ed: Steven J. Vaughan-Nichols has just joined this Linux FUD fest]
Now the insecurity firms rush to spread FUD and panic
“Dirty Pipe” Linux kernel bug lets anyone write to any file
Bug in the Linux Kernel Allows Privilege Escalation, Container Escape | Threatpost
Now Android sites
Dirty Pipe: What you need to know about the major exploit affecting Pixel 6 and Galaxy S22 devices
Linux Dirty Pipe kernel bug exposes Android to potential malware vector
More drama
The Dirty Pipe Vulnerability
Serious flaw in Linux kernel patched, exploits released
Spamnil's site joins the FUD club
‘Dirty Pipe’ Linux Vulnerability Allows Overwriting Data In Arbitrary Read-Only Files
Spreading falsehoods for the anti-Linux media operatives
"Dirty Pipe" Is The Worst Linux Exploit In Years - Invidious
How to hype up local privilege escalation
Cyber Security Today, March 9, 2022 – Warnings to Linux and HP device administrators, Samsung confirms data theft and more | IT World Canada News
CISA
Dirty Pipe Privilege Escalation Vulnerability in Linux
A fairer headline/coverage
Dirty Pipe Makes Linux Privilege Escalation Easy
The media likes to make it sound like Linux is the worst
What Is the Dirty Pipe Exploit in Linux and How Can You Fix It?
New twists of 'flavours' of the FUD
Linux vulnerability allowed root-level access | SC Media
Dirty Pipe root Linux vulnerability can also impact containers | CSO Online
Microsoft boosters amplify this, as it helps deflect
This Week in IT - Linux Gets Its Pipes Dirty
Shoveling up FUD to distract from Microsoft's back doors
Linux bug Dirty Pipe a 'serious vulnerability,' could affect Steam Decks [Ed: Shoveling up FUD to distract from Microsoft's back doors]
Dirty Pipe: The Latest Serious Linux Kernel Vulnerability...
Dirty Pipe: The Latest Serious Linux Kernel Vulnerability is Being Patched
Might be bot-generated
CVE-2022-0847: Arbitrary File Overwrite Vulnerability in Linux Kernel | MarketScreener
Still in some headlines
Week in review: Linux bug gives root access to attackers, UPS devices’ vulns, IoT security for OEMs [Ed: Still in some headlines]
Linux Kernel Bug Called 'Dirty Pipe' Discovered, Emergency Patch Released
Microsofters have found a new angle for attacking Linux, recycle
QNAP warns severe Linux bug affects most of its NAS devices
'Dirty Pipe' Linux Flaw Affects a Wide Range of QNAP NAS Devices
‘Dirty Pipe’ security patched kernels available
‘Dirty Pipe’ security patched kernels available
Microsoft friendly media finding new excuses to recycle panic
Dirty Pipe: What you need to know about the major exploit affecting Pixel 6 and Galaxy S22 devices [Updated] [Ed: Microsoft friendly media finding new excuses to recycle last week's panic]
Dirty Pipe Exploit Rings Alarm Bells in the Linux Community
Dirty Pipe Flaw in Linux Kernel Lets Hackers Overwrite Root Files, Escalate Privileges
LINUX HAS BEEN SMOKED BY A DIRTY PIPE
Android Smartphone Users, Watch Out for This New Security Risk Called ‘Dirty Pipe’
QNAP Issues Warning Over Dirty Pipe Linux Exploit
JFrog : DirtyPipe (CVE-2022-0847) – the new DirtyCoW?
Dirty Pipe vulnerability: Is your Chromebook affected?
‘Dirty Pipe’ vulnerability can leave your Galaxy S22 open to hacker attacks
Linux has a big hole
ANDROID 12 FLAW ALLOWS HACKING SOME SMARTPHONES INCLUDING GALAXY S22
Android smartphones affected by vulnerability in Linux
Expert Reacted On ‘Dirty Pipe’ Linux Vulnerability
Dirty Pipe Vulnerability: Everything You Should be Knowing
PSA: Dirty Pipe, the Linux kernel root vulnerability, can be abused on the Samsung Galaxy S22 and Google Pixel 6 Pro
Pixel 6 Pro and Galaxy S22 fully owned in Dirty Pipe exploit demo
Nasty Linux netfilter firewall security hole found
Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw
QNAP NAS devices vulnerable to dangerous 'DirtyPipe' Linux bug
NAS Vendor Says Several of Its Products Likely Contain Linux 'Dirty Pipe' Flaw
Why is this scare back so suddenly?
New Linux bug elevated privileges and arbitrary code execution [Ed: Why is this scare back so suddenly?]