A new Linux vulnerability, known as "Dirty Pipe," allows local users to gain root privileges via publicly available exploits.

See also: Bvp47 Linux backdoor went undetected for 10 years
Security researcher Max Kellermann disclosed the "Dirty Pipe" vulnerability and stated that it affects Linux Kernel 5.8 and later versions, even on Android.
The vulnerability is known as CVE-2022-0847 and allows an unprivileged user to insert and overwrite data in read-only files, including SUID running as root.
Kellerman discovered the bug after spotting another bug that was corrupting web server access logs for one of his clients.
Kellerman states that the vulnerability is similar to the Dirty COW (CVE-2016-5195) that was patched in 2016.
As part of the Dirty Pipe disclosure, Kellerman released a PoC that allows local users to insert their own data into sensitive read-only files by removing restrictions or modifying configurations to provide greater access than usual.
See also: Google: Doubles rewards for Linux Kernel Zero-days

Security researcher Phith0n showed how malicious users could use the exploit to modify a file so that the root user does not have a password. Once this change is made, the unprivileged user could simply run the 'su root' command to gain access to the root account.
The vulnerability was responsibly disclosed to various Linux maintainers as of February 20, 2022, including the Linux kernel security team and the Android security team.
While the bug has been fixed in Linux kernels 5.16.11, 5.15.25 , and 5.10.102, many servers continue to run outdated kernels making the release of this exploit a significant issue for server administrators.
Furthermore, due to the ease of gaining root privileges using these exploits, it is only a matter of time before threat actors start using the vulnerability in their attacks. The similar Dirty COW vulnerability has been used by malware in the past, although it was more difficult to exploit.
See also: Kali Linux 2022.1: Released with 6 new tools
This bug is particularly concerning for web hosting providers that offer Linux shell access or universities that routinely provide shell access to multi-user Linux systems.
