Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


    Cloudron Forum

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Critical Kernel Bug: The Dirty Pipe Vulnerability

    Support
    security kernel
    2
    2
    290
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • nj
      nj last edited by girish

      I recently came across this post https://dirtypipe.cm4all.com/. Looks like everyone needs to look at this. What can be done to update the Kernel version, @girish @nebulon ?

      Timeline

      • 2021-04-29: first support ticket about file corruption

      • 2022-02-19: file corruption problem identified as Linux kernel bug, which turned out to be an exploitable vulnerability

      • 2022-02-20: bug report, exploit and patch sent to the Linux kernel security team

      • 2022-02-21: bug reproduced on Google Pixel 6; bug report sent to the Android Security Team

      • 2022-02-21: patch sent to LKML (without vulnerability details) as suggested by Linus Torvalds, Willy Tarreau and Al Viro

      • 2022-02-23: Linux stable releases with my bug fix (5.16.11, 5.15.25, 5.10.102)

      • 2022-02-24: Google merges my bug fix into the Android kernel

      • 2022-02-28: notified the linux-distros mailing list

      • 2022-03-07: public disclosure

      Founder & OpenSource Lover. My Cloudron Apps

      nebulon 1 Reply Last reply Reply Quote 1
      • nebulon
        nebulon Staff @nj last edited by

        @nj Cloudro relies on Ubuntu LTS versions and security updates are enabled automatically (independent from Cloudron releases). So once the ubuntu securty team updates the kernels, all Cloudrons will get is as well. Since this is a kernel issue, you will likely see some "reboot required" notification in your Cloudron dashboard afterwards.

        1 Reply Last reply Reply Quote 3
        • First post
          Last post
        Powered by NodeBB