Pixel 6, Samsung Galaxy S22 Series, Other Android 12 Devices Vulnerable to Attacks Due to ‘Dirty Pipe’ Bug

Google is already aware of the security issue but is yet to confirm its fix.

Advertisement
By Jagmeet Singh | Updated: 9 March 2022 19:31 IST
Highlights
  • ‘Dirty Pipe’ vulnerability first appeared on Linux kernel version 5.8
  • Google merged the bug fix given by a researcher into the Android kernel
  • The vulnerability could allow attackers to gain full root access

Google Pixel 6 was used to reproduce the highly severe bug

Photo Credit: Unsplash/ Jonas Elia

Google Pixel 6, Samsung Galaxy S22, and some other new devices running on Android 12 are affected by a highly severe Linux kernel vulnerability called “Dirty Pipe.” The vulnerability can be exploited by a malicious app to gain system-level access and overwrite data in read-only files on the system. First noticed on the Linux kernel, the bug was reproduced by a security researcher on Pixel 6. Google was also informed about its existence to introduce a system update with a patch.

Security researcher Max Kellermann of German Web development company CM4all spotted the ‘Dirty Pipe' vulnerability. Shortly after Kellermann publicly disclosed the security loophole this week that has been recorded as CVE-2022-0847, other researchers were able to detail its impact.

 

As per Kellermann, the issue existed in the Linux kernel since the version 5.8, though it was fixed in the Linux 5.16.11, 5.15.25, and 5.10.102. It is similar to the ‘Dirty COW' vulnerability but is easier to exploit, the researcher said.

Advertisement

The ‘Dirty COW' vulnerability had impacted Linux kernel versions created before 2018. It also impacted users on Android, though Google fixed the flaw by releasing a security patch back in December 2016.

Advertisement

An attacker exploiting the ‘Dirty Pipe' vulnerability can gain access to overwrite data in read-only files on the Linux system. It could also allow hackers to create unauthorised user accounts, modify scripts, and binaries by gaining backdoor access.

Since Android uses the Linux kernel as core, the vulnerability has a potential to impact smartphone users as well. It is, however, limited in nature as of now — thanks to the fact that most Android releases are not based on the Linux kernel versions that are affected by the flaw.

Advertisement

“Android before version 12 is not affected at all, and some Android 12 devices — but not all — are affected,” Kellermann told Gadgets 360.

The researcher also said that if the device was vulnerable, the bug could be used to gain full root access. This means that it could be used to allow an app to read and manipulate encrypted WhatsApp messages, capture validation SMS messages, impersonate users on arbitrary websites, and even remotely control any banking apps installed on the device to steal money from the user.

Advertisement

Kellermann was able to reproduce the bug on Google Pixel 6 and reported its details to the Android security team in February. Google also merged the bug fix into the Android kernel shortly after it received the report from the researcher.

However, it is unclear whether the bug has been fixed through the March security patch that was released earlier this week.

In addition to the Pixel 6, the Samsung Galaxy S22 devices appear to be impacted by the bug, according to Ars Technica's Ron Amadeo.

Some other devices that are running on Android 12 out-of-the-box are also expected to be vulnerable to attacks due to the ‘Dirty Pipe' issue.

Gadgets 360 reached out to Samsung for clarity on the vulnerability, and the company responded by saying that it is releasing the security updates to address the issue soon. Google, though, didn't respond to a request for comment on the matter.

Meanwhile, users are recommended to not install apps from any third-party sources. It is also important to avoid installing any untrusted apps and games, and make sure to have the latest security patches installed on the device.


What should you know about MWC 2022? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Small and compact
  • Quality AMOLED display
  • Impressive performance
  • Good battery life
  • IP68 rated
  • Bad
  • Heats up easily with camera use
  • No bundled charger
 
KEY SPECS
Display 6.10-inch
Processor Qualcomm Snapdragon 8 Gen 1
Rear Camera Unspecified
RAM 8GB
Storage 128GB, 256GB
Battery Capacity 3,700mAh
OS Android 12
NEWS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Quality AMOLED display
  • Impressive performance
  • Good battery life
  • IP68 rated
  • Bad
  • Heats up easily with camera use
  • No bundled charger
  • Not the best value offering in the series
 
KEY SPECS
Display 6.60-inch
Processor Qualcomm Snapdragon 8 Gen 1
Front Camera 10-megapixel
Rear Camera 50-megapixel + 12-megapixel + 10-megapixel + 10-megapixel
RAM 8GB
Storage 128GB, 256GB
Battery Capacity 4,500mAh
OS Android 12
NEWS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • In-built S Pen stylus
  • Superb display
  • Impressive performance
  • Versatile cameras
  • Good battery life
  • IP68 rated
  • Bad
  • Gets warm easily under load
  • Big and bulky
  • No bundled charger
  • Expensive
 
KEY SPECS
Display 6.80-inch
Processor Qualcomm Snapdragon 8 Gen 1
Front Camera 40-megapixel
Rear Camera 108-megapixel + 12-megapixel + 10-megapixel
RAM 8GB, 12GB
Storage 128GB, 256GB, 512GB, 1TB
Battery Capacity 5000mAh
OS Android 12
NEWS

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo F31 Series Specifications Confirmed Ahead of India Launch
  2. Samsung Galaxy F17 5G With 5,000mAh Battery Launched in India
  3. Samsung Galaxy S25 FE Tipped to Go On Sale At This Price in India
  4. iPhone 14 Under Rs. 40,000: Flipkart's Big Billion Days Deal Revealed
  5. Flipkart BBD Deal: iPhone 16 Pro Max Under Rs. 90,000
  6. OTT Releases This Week: Coolie, Saiyaara, a Tamannaah Bhatia Web Series
  7. Experts Warn Against Charlie Kirk Tokens Amidst Backlash, Volatility
  8. HMD Vibe 5G Launched in India Alongside HMD 101 4G and HMD 102 4G
  9. Samsung Galaxy S26 Ultra May Feature Downgraded 3x Telephoto Camera
  10. You Can Now Sign Up to Test Xiaomi's HyperOS 3 Update
  1. Saiyaara Is Now Streaming on Netflix: All You Need to Know About The Ahaan Pandey, Aneet Padda Starrer
  2. SpaceX Falcon 9 Launches 21 Satellites for US Military’s New Communications Network
  3. NASA Uses Rocky Mountain Helicopter Drills to Prepare Astronauts for Artemis Moon Missions
  4. NASA’s Perseverance Rover Finds Potential Signs of Life in Mars Rock Sample
  5. iPhone 14 Under Rs. 40,000: Flipkart's Big Billion Days Sale Deal Revealed
  6. Forget iPhone 17 Pro, Get the iPhone 16 Pro Max for Under Rs. 90,000 in Flipkart's Big Billion Days Sale
  7. Supermoon 2025: When Is the Next Full Moon Lighting Up the Sky
  8. New Black Hole Merger Gives Clearest Test of Einstein’s Relativity
  9. Only Murders in the Building Season 5 Now Streaming Online: Know When and Where to Watch
  10. Sony Launches PlayStation Family App on iOS, Android for Parental Controls on Gaming Activity
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.