Bug 2186545 (CVE-2022-20572) - CVE-2022-20572 kernel: missing DM_TARGET_IMMUTABLE feature flag in verity_target in drivers/md/dm-verity-target.c
Summary: CVE-2022-20572 kernel: missing DM_TARGET_IMMUTABLE feature flag in verity_tar...
Keywords:
Status: NEW
Alias: CVE-2022-20572
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2012340 2090507 2187486 2187487 2187488 2187489
Blocks: 2186254
TreeView+ depends on / blocked
 
Reported: 2023-04-13 16:49 UTC by Guilherme de Almeida Suckevicz
Modified: 2024-02-15 20:26 UTC (History)
43 users (show)

Fixed In Version: kernel 5.19
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the Linux kernel, where it is possible to modify read-only files due to a missing permission check. This flaw can lead to local privilege escalation.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2023-04-13 16:49:42 UTC
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-234475629References: Upstream kernel

Reference:
https://source.android.com/security/bulletin/pixel/2022-12-01

Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4caae58406f8ceb741603eee460d79bacca9b1b5

Comment 3 Guilherme de Almeida Suckevicz 2023-05-02 16:50:00 UTC
This issue was fixed in upstream in version 5.19. The kernel packages as shipped in the following Red Hat products were previously updated to a version that contains the fix via the following errata:

kernel in Red Hat Enterprise Linux 8
https://access.redhat.com/errata/RHSA-2022:7683

kernel-rt in Red Hat Enterprise Linux 8
https://access.redhat.com/errata/RHSA-2022:7444

kernel in Red Hat Enterprise Linux 9
https://access.redhat.com/errata/RHSA-2022:8267

kernel-rt in Red Hat Enterprise Linux 9
https://access.redhat.com/errata/RHSA-2022:7933


Note You need to log in before you can comment on or make changes to this bug.