Перейти к содержанию

PinTheft vulnerability in Linux kernel patched in ROSA "Khrom" OS

The danger of PinTheft lies in the fact that vulnerabilities of this class allow an attack to be developed after limited access has already been obtained.

Russian developer NTC IT "ROSA" has released an update for ROSA "Khrom" 12, ROSA "Khrom" 12 FSTEC, and ROSA "Khrom" 13 operating systems, patching the PinTheft vulnerability in the Linux kernel. The vulnerability allows a local user to escalate privileges to root.

PinTheft is another Copy Fail class vulnerability related to the ability to overwrite data in the Linux page cache. Technically, the problem is associated with an error in the RDS network protocol, used for message exchange between cluster nodes.

Exploitation requires prior access to the system and execution of code as a regular user. NTC IT "ROSA" explained:

The danger of PinTheft lies in the fact that vulnerabilities of this class allow an attack to be developed after limited access has already been obtained. In corporate infrastructure, this is especially important for developer workstations, servers, CI/CD environments, virtualization systems, and other environments where user or third-party code may be executed.

The update is available through the standard OS update mechanism; after installation, the system must be rebooted.