malware

Kernel bug exposes Android to potential malware – Linux Dirty Pipe

Robert Haba
Robert HabaFounder · Editor-in-Chief
PublishedMarch 9, 2022
Read Time2 Mins
Trust this source on Google
Add trusted source

If Android were a car engine, and you popped the hood and poked around a bit, you’d find the label “Linux” etched on the engine block. The open-source operating system provides the starting point that Android’s built on top of, but sharing code also means sharing vulnerabilities. Now a newly discovered Linux kernel bug is raising concerns for the security of Android devices, as it leaves a door open for malware intrusion.

The glitch in question has been dubbed “Dirty Pipe” by software engineer Max Kellerman, who provides a detailed writeup about the bug’s discovery. He first spotted some mysteriously corrupted log files last year, and his analysis of the problem revealed a kernel-level flaw that’s existed since 2020. The vulnerability lets software overwrite the system page cache, even for files where apps shouldn’t otherwise have permission. He determined that in the wrong hands the issue had potential for exploitation and alerted the team behind Linux kernel security. Properly coded malware could use this method to obtain full control of a vulnerable system by overwriting files as vital as the system’s root password.

Kellerman was also able to reproduce the bug on a Pixel 6, and reached out to let Google know. The company similarly prepared a fix, and merged it into the Android kernel. Right now, it’s just a matter of OEMs needing to incorporate that fixed kernel in future device updates.

For what it’s worth, Google confirmed to Android Police that Dirty Pipe did not play a role in delaying the release of Android 12L for the Pixel 6. Linux users, meanwhile, need to install their distro’s most recent security updates ASAP.

Robert Haba
Founder · Editor-in-Chief
Follow:X
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Google Pixel’s “Take a Message” Feature May Soon Expand to More Countries and Non-Pixel Devices

Google Pixel’s “Take a Message” Feature May Soon Expand to More Countries and Non-Pixel Devices

Being a Pixel owner outside the United States has always come with a catch: a long list of AI features that simply aren’t available in your region. Google has gradually extended some of these to international markets, but the majority remain US-only. That gap may be getting a little smaller, as the company appears to […]

Qualcomm Snapdragon 4 Gen 5 and Snapdragon 6 Gen 5 Announced with Faster GPUs and New Connectivity

Qualcomm Snapdragon 4 Gen 5 and Snapdragon 6 Gen 5 Announced with Faster GPUs and New Connectivity

Qualcomm usually makes headlines for its top-tier Snapdragon 8 Elite series, and while those chips may end up inside the most expensive and desirable phones this year, the company also has a lineup of processors built for more modest hardware. Today, that means two new chips worth paying attention to. The Snapdragon 4 Gen 5 […]

Xiaomi MIX Fold 5 Spotted with XRING O3 Chipset in Mi Code Leak

Xiaomi MIX Fold 5 Spotted with XRING O3 Chipset in Mi Code Leak

Fresh clues from the Mi Code database point to Xiaomi’s next foldable flagship making a comeback. After scrapping last year’s prototype, the company seems more committed than ever to foldables, with a device that hits a key hardware milestone: Xiaomi’s first foldable running its own silicon. The Foldable Comeback and XRING O3 Mi Code data […]

TSMC Breaks 5GHz Barrier on Mobile Chips

TSMC Breaks 5GHz Barrier on Mobile Chips

With its advanced nodes enabling smartphone chipsets to achieve clock speeds of up to 5GHz, TSMC would achieve yet another significant milestone this year. TSMC’s cutting-edge technology have already tremendously benefited companies like Qualcomm, MediaTek, and Apple. Later this year, new chips will achieve peak clock rates of up to 5GHz for the first time […]