Mar 14, 2022
Security updates: Linux® kernel vulnerability
A vulnerability called "Dirty Pipe" (CVE-2022-0847) allows users to increase their access via the page cache. Aiven's CISO writes about our mitigating actions.
![james-arlen](https://cdn.sanity.io/images/sczeoy4w/production/2ce9dc63f72b09eb3dcba4d7d5998ce8a5a3d873-1000x1000.jpg?w=100&h=100&q=80&fit=min&auto=format&dpr=1.5)
James Arlen
|RSS FeedChief Information Security Officer at Aiven
On 7th March 2022, we became aware of CVE-2022-0847, also known as "Dirty Pipe". This vulnerability allows an unprivileged local user to write to pages in the page cache backed by read-only files. They could use this to increase their access to the system further by enhancing their privileges.
Current Status
An optional maintenance update will be made available to all customers which will patch them against this issue and can be implemented using the normal maintenance application functions already in use. Over the next 30 days, the optional update will be made mandatory and rolled out to all customers.
Impact on Aiven Services
The Aiven platform does not allow direct interaction with the underlying operating system. Additionally, Aiven’s architecture prevents cross-tenant impact from vulnerabilities such as this.
Our product and infrastructure security teams have reviewed our existing mitigations in context with this particular vulnerability. Furthermore, internal monitoring has been extended to help identify any exploitation attempts.
Further Information
For more information about the vulnerability, see CVE-2022-0847.
Subscribe to the Aiven newsletter
All things open source, plus our product updates and news in a monthly newsletter.
Related resources
Feb 3, 2023
Major version updates for your PostgreSQL in seconds? Yes, Aiven can do it! Come and find out more.
Mar 20, 2024
Aiven for Dragonfly delivers a 700% performance boost to scale with your enterprise needs
May 20, 2024
Changing regulations are requiring FSIs to increase their resilience and protect their operations and customers against misadventure or attack.