{"id":103489,"date":"2022-03-07T21:36:38","date_gmt":"2022-03-07T19:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya"},"modified":"2022-03-07T21:36:38","modified_gmt":"2022-03-07T19:36:38","slug":"uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya","title":{"rendered":"Vulnerabilidad en el n\u00facleo de Linux que permite modificar archivos solo de lectura","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha identificado una vulnerabilidad en el n\u00facleo de Linux (CVE-2022-0847) que permite sobrescribir el contenido de la cach\u00e9 de p\u00e1gina para cualquier archivo, incluyendo aquellos en modo solo lectura, abiertos con el flag O_RDONLY o ubicados en sistemas de archivos montados en modo solo lectura. Desde un punto de vista pr\u00e1ctico, la vulnerabilidad puede ser utilizada para inyectar c\u00f3digo en procesos arbitrarios o alterar datos en archivos abiertos. Por ejemplo, se puede modificar el contenido del archivo authorized_keys para el proceso sshd. Se dispone de un prototipo de exploit para su prueba.     <\/p>\n<p>A la problem\u00e1tica se le ha asignado el nombre en clave Dirty Pipe, en analog\u00eda con la cr\u00edtica vulnerabilidad Dirty COW descubierta en 2016. Se se\u00f1ala que, en t\u00e9rminos de nivel de peligro, Dirty Pipe se sit\u00faa a la par con Dirty COW, pero es considerablemente m\u00e1s f\u00e1cil de explotar. La vulnerabilidad se identific\u00f3 durante la revisi\u00f3n de quejas sobre la corrupci\u00f3n peri\u00f3dica de archivos descargados a trav\u00e9s de la red en un sistema que carga archivos comprimidos desde un servidor de logs (37 corrupciones en 3 meses en un sistema con alta carga), donde se utiliz\u00f3 la operaci\u00f3n splice() y tuber\u00edas an\u00f3nimas.      <\/p>\n<p>La vulnerabilidad se manifiesta a partir del n\u00facleo de Linux 5.8, lanzado en agosto de 2020, es decir, est\u00e1 presente en Debian 11, pero no afecta el n\u00facleo base en Ubuntu 20.04 LTS. Los n\u00facleos de RHEL 8.x y openSUSE\/SUSE 15 se basan inicialmente en ramas antiguas, pero no se puede descartar que la modificaci\u00f3n que caus\u00f3 el problema haya sido retroportada en ellos (no hay datos exactos por el momento). Se puede hacer seguimiento a las publicaciones de actualizaciones de paquetes en las siguientes p\u00e1ginas: Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux. Se ha propuesto una correcci\u00f3n para la vulnerabilidad en las versiones 5.16.11, 5.15.25 y 5.10.102. La correcci\u00f3n tambi\u00e9n ha sido incluida en el n\u00facleo utilizado en la plataforma Android.    <\/p>\n<p>La vulnerabilidad es causada por la falta de inicializaci\u00f3n del valor \u00abbuf-&gt;flags\u00bb en el c\u00f3digo de las funciones copy_page_to_iter_pipe() y push_pipe(), dado que la memoria no se limpia al asignar la estructura, y debido a ciertas manipulaciones con canales an\u00f3nimos, puede haber un valor de otra operaci\u00f3n en \u00abbuf-&gt;flags\u00bb. Aprovechando esta particularidad, un usuario local no privilegiado puede hacer que aparezca en la bandera el valor PIPE_BUF_FLAG_CAN_MERGE, lo que permite la reescritura de datos en la cach\u00e9 de p\u00e1ginas simplemente escribiendo nuevos datos en un canal an\u00f3nimo preparado espec\u00edficamente.        <\/p>\n<p> Para llevar a cabo el ataque, el archivo objetivo debe estar disponible para lectura, y dado que al escribir en el pipe no se verifican los permisos de acceso, la sustituci\u00f3n en la cach\u00e9 de p\u00e1ginas puede realizarse incluso para archivos que se encuentran en secciones montadas solo para lectura (por ejemplo, archivos de un CD-ROM). Despu\u00e9s de reemplazar la informaci\u00f3n en la cach\u00e9 de p\u00e1ginas, el proceso al leer datos desde el archivo obtendr\u00e1 datos no reales, sino sustituidos.      <\/p>\n<p>La explotaci\u00f3n consiste en crear un canal sin nombre y llenarlo con datos arbitrarios para lograr que se establezca el flag PIPE_BUF_FLAG_CAN_MERGE en todas las estructuras de anillo relacionadas. Luego, los datos se leen desde el canal, pero el flag permanece establecido en todas las instancias de la estructura pipe_buffer en las estructuras anulares pipe_inode_info. Luego se realiza una llamada a splice() para leer datos desde el archivo objetivo al canal sin nombre, comenzando desde el desplazamiento requerido. Al escribir datos en este canal sin nombre, debido al flag establecido PIPE_BUF_FLAG_CAN_MERGE, los datos en la cach\u00e9 de p\u00e1ginas ser\u00e1n sobrescritos en lugar de crear una nueva instancia de la estructura pipe_buffer.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56818\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-0847), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u0433\u043e \u043a\u044d\u0448\u0430 \u0434\u043b\u044f \u043b\u044e\u0431\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u043d\u0430\u0445\u043e\u0434\u044f\u0449\u0438\u0445\u0441\u044f \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f, \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c O_RDONLY \u0438\u043b\u0438 \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u0432 \u0444\u0430\u0439\u043b\u043e\u0432\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445, \u043f\u0440\u0438\u043c\u043e\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f. \u0421 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b, \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043a\u043e\u0434\u0430 \u0432 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u044b \u0438\u043b\u0438 \u0438\u0441\u043a\u0430\u0436\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c\u044b\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103489","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-0847), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u0433\u043e \u043a\u044d\u0448\u0430 \u0434\u043b\u044f \u043b\u044e\u0431\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u043d\u0430\u0445\u043e\u0434\u044f\u0449\u0438\u0445\u0441\u044f \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f, \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c O_RDONLY \u0438\u043b\u0438 \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0438\u0441\u043a\u0430\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-0847), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u0433\u043e \u043a\u044d\u0448\u0430 \u0434\u043b\u044f \u043b\u044e\u0431\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u043d\u0430\u0445\u043e\u0434\u044f\u0449\u0438\u0445\u0441\u044f \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f, \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c O_RDONLY \u0438\u043b\u0438 \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-03-07T19:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-03-07T19:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilidad en el n\u00facleo de Linux que permite alterar archivos disponibles solo para lectura | ProHoster","description":"Se ha identificado una vulnerabilidad en el n\u00facleo de Linux (CVE-2022-0847) que permite sobrescribir el contenido de la cach\u00e9 de p\u00e1ginas para cualquier archivo, incluidos aquellos en modo solo lectura, que se abran con la bandera O_RDONLY o que est\u00e9n ubicados.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u044f\u0434\u0440\u0435 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0438\u0441\u043a\u0430\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f | ProHoster","og:description":"\u0412 \u044f\u0434\u0440\u0435 Linux \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-0847), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u043e\u0433\u043e \u043a\u044d\u0448\u0430 \u0434\u043b\u044f \u043b\u044e\u0431\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u043d\u0430\u0445\u043e\u0434\u044f\u0449\u0438\u0445\u0441\u044f \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f, \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c O_RDONLY \u0438\u043b\u0438 \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-yadre-linux-pozvolyayushhaya-iskazit-fajly-dostupnye-tolko-dlya-chteniya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-03-07T19:36:38+00:00","article:modified_time":"2022-03-07T19:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103489","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-03-07 19:37:31","updated":"2022-10-03 12:20:49","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/103489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=103489"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/103489\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=103489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=103489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=103489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}