Security Vulnerability: Dirty Pipe attack (CVE-2022-0847)
This document (000020603) is provided subject to the disclaimer at the end of this document.
Environment
https://suse.com/security/cve/CVE-2022-0847.html
Situation
The attack is possible due to two separate bugs, one introduced in Linux Kernel 4.9, and another introduced in the Linux Kernel 5.8.
SUSE Linux Enterprise products use Linux Kernels older than 5.8, so these are not exploitable by default.
Products based on Linux Kernel 4.12 and 5.3 will receive updates for the first bug referenced by this CVE.
Resolution
To install the respective patch, please use:
zypper patch --cve=CVE-2022-0847
Status
Additional Information
Disclaimer
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:000020603
- Creation Date: 08-Mar-2022
- Modified Date:08-Mar-2022
-
- SUSE Enterprise Storage
- SUSE Linux Enterprise Real Time
- SUSE Linux Enterprise Server
- SUSE Manager
- SUSE Linux Enterprise Micro
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com