[00:24] FYI https://ubuntu.com/security/notices/USN-5317-1 is out and covers dirty pipe [00:25] aka CVE-2022-0847 [00:25] A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the syste... [15:11] RE: cve-2022-0847, there's some confusion about "Needed" for Bionic and Focal - https://askubuntu.com/questions/1396716/why-is-linux-in-bionic-and-focal-affected-by-cve-2022-0847 [15:11] A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the syste... [15:11] should I be bothering the kernel team or is the Security team aware of whether this is/isn't patched in Bionic and Focal kernels? [15:11] my understanding of "needed" in the tracker is a little bit ambiguous. [15:13] the flaw exists in bionic and focal, but it's not exploitable [15:13] (yet) [15:13] mdeslaur: check, mind if I quote you? [15:13] we will patch bionic and focal during the next round of kernel updates [15:13] just in case someone discovers another way to exploit the flaw [15:13] I don't mind [15:15] mdeslaur: thanks. i always ask before direct quoting :) [15:15] thanks for the clarification! [15:22] np [15:57] I've added a note to the CVE, the website should get updated in a few minutes [17:00] mdeslaur: perfect, glad to hear the notes/comments got updated with clarification. [17:00] always like how when these kinds of things show up here it ends up with updates to the tracker ;) [17:53] teward: thanks for bringing them up! [17:54] yep, always happy to divert security questions your way when they're on ask ubuntu. an advantage of me knowing where to connect :P [17:55] s/where to connect/who to contact/ [18:51] :)