QNAP is warning that most of its Network Attached Storage (NAS) devices are affected by a serious Linux vulnerability called “Dirty Pipe” that allows attackers with local access to gain root privileges.
Learn more: Linux bug gives root privileges to all major distributions

The “Dirty Pipe” vulnerability affects Linux 5.8 and later Kernel versions , including Android devices. If successfully exploited, it allows non-privileged users to insert and replace data in read-only files, including SUID processes running as root.
Security researcher Max Kellermann, who found and reported the flaw, also released a proof-of-concept (PoC) exploit that allows local users to modify configurations and gain higher privileges and access.
The vulnerability became widely known a few days ago, and a patch was released last week with Linux kernel versions 5.16.11, 5.15.25, and 5.10.102 . However, QNAP says its customers should wait for the company to release security updates. That's the only way they can protect themselves.
" If exploited, this vulnerability could allow a user to gain administrator privileges and inject malicious code ," QNAP explained
"Currently, there are no mitigation methods for this vulnerability. We recommend that users check back and install security updates as they become available," the company said.
See also: How are cyberattacks dealt with in data centers?

“Dirty Pipe” vulnerability affects NAS devices running kernel version 5.10.60
The company says the bug affects devices running QTS 5.0.x and QuTS hero h5.0.x, including:
- QTS 5.0.x on all QNAP x86-based NAS and some QNAP ARM-based NAS
- QuTS hero h5.0.x on all QNAP x86-based NAS and some QNAP ARM-based NAS
You can find a full list of all affected models on this page under the entry “Kernel Version 5.10.60.” According to QNAP, none of its NAS devices running QTS 4.x are affected and are not vulnerable to attacks.
Therefore, users should wait for QNAP to release security updates to address the Dirty Pipe vulnerability. Until then, users can take some measures, such as ensuring that the NAS device is not exposed to Internet attacks. This way, they can prevent attempts to gain local access.
See also: “Escobar” banking trojan steals Google Authenticator MFA codes
Customers who have NAS devices exposed to the Internet should take the following steps to defend themselves:
- Disable the router's Port Forwarding function: Go to the router's management interface, check the Virtual Server, NAT, or Port Forwarding settings, and disable the port forwarding setting of the NAS management service port (ports 8080 and 433 by default).
- Disable the UPnP function of QNAP NAS: Go to myQNAPcloud in the QTS menu, click “Auto Router Configuration” and uncheck “Enable UPnP Port Forwarding”.
QNAP also provides guidance on how users can protect themselves from attacks.
Source: Bleeping Computer
