Dataprise Defense Digest 550x550

EXECUTIVE SUMMARY:

On March 8th, 2022 researchers discovered a vulnerability that allows for overwriting arbitrary read-only values, including /etc/shadow, allowing unprivileged actors to overwrite values and execute privileged processes as root. This vulnerability is considered high severity and affects all Linux kernel versions since 5.8. This vulnerability requires a user to have access to at least a low-level authorized user account to escalate privileges, therefore this vulnerability is assessed to be a High priority for patches and a Medium priority for exploitation as Proof of Concept code is available.

Severity: 8 (High)

IMPACT

Privilege Escalation; Low privilege authenticated users can run processes or inject data as root

DETAILED ANALYSIS

Pipe buffer flags allow merging commands which can allow instructions in the 4kb memory page buffer to overflow and write to additional processes or files as root. The practical application of this vulnerability is to overwrite the /etc/shadow file, or to tie in a process execution allowing for the process to be run with root privileges for any file or process currently in the page cache.

This vulnerability is in Linux kernels 5.8 and higher due to an uninitialized “pipe_buffer.flags” variable.

**NOTE: The file write or process executed cannot be run outside of the page boundary, i.e. no execution or writes across multiple pages of memory. All execution is limited to the 4kb block targeted.

INDICATORS OF VULNERABILITY

Any system using Linux kernels 5.16.11, 5.15.25, and 5.10.102, or below are vulnerable. Unfortunately, server admins continue to run outdated kernels and this can be significantly disruptive to update.

This is especially troubling for web hosting providers offering shell access.

MITIGATION

Update to Linux kernels 5.16.11, 5.15.25, and 5.10.102.


SOURCES

https://www.bleepingcomputer.com/news/security/new-linux-bug-gives-root-on-all-major-distros-exploit-released
https://www.zdnet.com/article/how-many-linux-users-are-there-anyway/
https://hostingtribunal.com/blog/linux-statistics/#gref
https://www.top500.org/statistics/details/osfam/1/
https://ubuntu.com/security/CVE-2022-0847
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0847
https://dirtypipe.cm4all.com/ (Detailed technical release from vulnerability discovery)
https://haxx.in/files/dirtypipez.c (POC code)

 

AUTHORS

  • Bryan Austin, Senior Cybersecurity Project Engineer
  • Sam Bourgeois, vCISO
  • Stephen Jones, Vice President – Cybersecurity Services

If you have any questions, please reach out to the Dataprise Security Operations Center at [email protected].

Dataprise

Dataprise is a national managed service provider that believes that technology should enable our clients to be the absolute best at what they do.

Let’s talk IT.

Request a consultation. Tell us where your offices are and one of our engineers will be in touch within one business day — no sales script, no obligation, just a working conversation about what you’re trying to do.

cyber insurance

"*" indicates required fields

Your Name*