Kernel bug exposes Android to potential malware – Linux Dirty Pipe

Robert Haba
By
Robert Haba
News Writer · Droid Tools
Robert Haba covers breaking Android news, chipset leaks, and OEM announcements at Droid Tools. With 7 years tracking the Android ecosystem, he has followed every major...
- News Writer · Droid Tools
2 Min Read
Trust this source on Google
Always see our content first in your search results
Add trusted source

If Android were a car engine, and you popped the hood and poked around a bit, you’d find the label “Linux” etched on the engine block. The open-source operating system provides the starting point that Android’s built on top of, but sharing code also means sharing vulnerabilities. Now a newly discovered Linux kernel bug is raising concerns for the security of Android devices, as it leaves a door open for malware intrusion.

android malware 1

The glitch in question has been dubbed “Dirty Pipe” by software engineer Max Kellerman, who provides a detailed writeup about the bug’s discovery. He first spotted some mysteriously corrupted log files last year, and his analysis of the problem revealed a kernel-level flaw that’s existed since 2020. The vulnerability lets software overwrite the system page cache, even for files where apps shouldn’t otherwise have permission. He determined that in the wrong hands the issue had potential for exploitation and alerted the team behind Linux kernel security. Properly coded malware could use this method to obtain full control of a vulnerable system by overwriting files as vital as the system’s root password.

Kellerman was also able to reproduce the bug on a Pixel 6, and reached out to let Google know. The company similarly prepared a fix, and merged it into the Android kernel. Right now, it’s just a matter of OEMs needing to incorporate that fixed kernel in future device updates.

For what it’s worth, Google confirmed to Android Police that Dirty Pipe did not play a role in delaying the release of Android 12L for the Pixel 6. Linux users, meanwhile, need to install their distro’s most recent security updates ASAP.

Trust this source on Google
Always see our content first in your search results
Add trusted source
Share This Article
News Writer · Droid Tools
Follow:
Robert Haba covers breaking Android news, chipset leaks, and OEM announcements at Droid Tools. With 7 years tracking the Android ecosystem, he has followed every major Snapdragon generation, Pixel launch, and One UI release since 2015. Before joining Droid Tools, he covered consumer electronics at a local publication. Robert's coverage focuses on news and OS updates. When a story breaks, you'll find his analysis within the hour.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *