Broadcom API Gateway - CVE-2022-0847 "Dirty Pipe" vulnerability
search cancel

Broadcom API Gateway - CVE-2022-0847 "Dirty Pipe" vulnerability

book

Article ID: 236569

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

This vulnerability was publicly disclosed on March 7 2022 and rated with a severity impact of important. It affects the Linux kernel and allows an attacker to modify the contents of a file (either in memory or on disk) even when on read-only access mode.

Environment

Gateway Appliance 9.x/10.x

Cause

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialisation in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read-only files and as such escalate their privileges on the system.

Reference: https://access.redhat.com/security/cve/CVE-2022-0847

 

Resolution

Gateway Appliance version 9.x and 10.x is NOT impacted at this stage.

The vulnerability only affects Linux Kernel version 5.8 and above. Our appliance is based on Linux Kernel 3.x. Hence there's no need for mitigation steps to be taken.

Additional Information

To verify the exact Linux version running on the system, please run "uname -a

Here is an example: