** 説明
- CVE-2022-0847のPOC: Linuxカーネルのローカル権限昇格脆弱性。
- antxによって2022-03-08に作成されました。
** 詳細
- セキュリティ研究者のMax Kellermannは責任を持って'Dirty Pipe'脆弱性を開示し、Linuxカーネル5.8以降、Androidデバイスにも影響を与えると述べました。
- Linuxカーネル5.8以降の脆弱性で、任意の読み取り専用ファイルのデータを上書きできる。これにより、特権のないプロセスがルートプロセスにコードを注入できるため、権限昇格につながる。
- Linuxカーネルのcopy_page_to_iter_pipeおよびpush_pipe関数において、新しいパイプバッファ構造体の"flags"メンバーが適切に初期化されていないため、古い値が含まれる可能性があるという欠陥が見つかりました。特権のないローカルユーザーはこの欠陥を利用して、読み取り専用ファイルにバックアップされたページキャッシュ内のページに書き込み、システム上で権限を昇格させることができます。この欠陥は、5.17-rc6より前のLinuxカーネルバージョンに影響します。
- これは[[https://nvd.nist.gov/vuln/detail/CVE-2016-5195][CVE-2016-5195]] "Dirty Cow"に似ていますが、悪用がより簡単です。
- この脆弱性は、Linux 5.16.11、5.15.25、5.10.102で[[https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9d2231c5d74e13b2a0546fee6737ee4446017903][修正]]されました。
** CVE Severity
- attackComplexity: LOW
- attackVector: LOCAL
- availabilityImpact: -
- confidentialityImpact: -
- integrityImpact: HIGH
- privilegesRequired: -
- scope: -
- userInteraction: -
- version: 3.1
- baseScore: -
- baseSeverity: -
** 影響
- Linuxカーネル5.8以降、Androidデバイスも含む
** POC
- [[./CVE-2022-0847.c][Poc]]
** 参照
- Ref-Source
- [[https://dirtypipe.cm4all.com/][Dirty Pipe脆弱性]]
- [[https://github.com/Arinerron/CVE-2022-0847-DirtyPipe-Exploit][CVE-2022-0847-DirtyPipe-Exploit]]
- Ref-Article
- [[https://www.bleepingcomputer.com/news/security/new-linux-bug-gives-root-on-all-major-distros-exploit-released/][new-linux-bug-gives-root-on-all-major-distros-exploit-released]]
- Ref-Poc
- [[https://github.com/Al1ex/LinuxEelvation/tree/master/CVE-2022-0847][CVE-2022-0847]]
- [[https://github.com/imfiver/CVE-2022-0847][CVE-2022-0847]]
- [[https://github.com/lucksec/CVE-2022-0847][CVE-2022-0847]]
- [[https://github.com/bbaranoff/CVE-2022-0847][CVE-2022-0847]]
- Ref-Risk
- CVE
- Ref-Related
- [[https://nvd.nist.gov/vuln/detail/CVE-2016-5195][CVE-2016-5195]]