1 |
On Fri, Mar 11, 2022 at 10:06 AM Nikos Chantziaras <realnc@×××××.com> wrote: |
2 |
> |
3 |
> On 11/03/2022 17:06, Mark Knecht wrote: |
4 |
> > Is this related to the 'dirty pipe' vulnerability that has been in the |
5 |
> > news of late and has gotten patched in most distros in the last few |
6 |
> > days? |
7 |
> |
8 |
> In one of the discussions about the patch, it was mentioned that "a |
9 |
> couple of CVEs would have never happened" if this had been the default |
10 |
> to begin with. So, probably yes? |
11 |
> |
12 |
> |
13 |
|
14 |
My Kubuntu system is set to '1' but Ubuntu released a patchset for 15 |
15 |
CVEs including the dirty pipe and I didn't even know about this |
16 |
feature before this news so I have no idea if this was just changed |
17 |
here but I suspect it was. I'm on a much older kernel than most of you |
18 |
guys. |
19 |
|
20 |
To me the overriding idea of not letting any user, including root, |
21 |
mess around in a pipe makes logical sense, but as the OP has showed I |
22 |
guess there were valid uses for this feature pre-patch, and it seems |
23 |
that a user can override the feature by setting some bits if they need |
24 |
to and really think they know what they are doing. |
25 |
|
26 |
Thanks for the response, |
27 |
Mark |