/srv/irclogs.ubuntu.com/2022/03/09/#ubuntu-security.txt

sbeattieFYI https://ubuntu.com/security/notices/USN-5317-1 is out and covers dirty pipe00:24
sbeattieaka CVE-2022-084700:25
ubottuA flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the syste... <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0847>00:25
tewardRE: cve-2022-0847, there's some confusion about "Needed" for Bionic and Focal - https://askubuntu.com/questions/1396716/why-is-linux-in-bionic-and-focal-affected-by-cve-2022-084715:11
ubottuA flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the syste... <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0847>15:11
tewardshould I be bothering the kernel team or is the Security team aware of whether this is/isn't patched in Bionic and Focal kernels?15:11
tewardmy understanding of "needed" in the tracker is a little bit ambiguous.15:11
mdeslaurthe flaw exists in bionic and focal, but it's not exploitable15:13
mdeslaur(yet)15:13
tewardmdeslaur: check, mind if I quote you?15:13
mdeslaurwe will patch bionic and focal during the next round of kernel updates15:13
mdeslaurjust in case someone discovers another way to exploit the flaw15:13
mdeslaurI don't mind15:13
tewardmdeslaur: thanks.  i always ask before direct quoting :)15:15
fungithanks for the clarification!15:15
mdeslaurnp15:22
mdeslaurI've added a note to the CVE, the website should get updated in a few minutes15:57
tewardmdeslaur: perfect, glad to hear the notes/comments got updated with clarification.17:00
tewardalways like how when these kinds of things show up here it ends up with updates to the tracker ;)17:00
mdeslaurteward: thanks for bringing them up!17:53
tewardyep, always happy to divert security questions your way when they're on ask ubuntu.  an advantage of me knowing where to connect :P17:54
tewards/where to connect/who to contact/17:55
sarnold:)18:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!