Dirty Pipe vulnerability impacts on Barco products

Article number: [5640] - Legacy code: [12596]

Applicable to

A new Linux vulnerability was discovered CVE-2022-0847, aka Dirty Pipe in Linux kernel.

CVE-2022-0847 is a vulnerability in the Linux kernel since v.5.8 which allows overwriting data in arbitrary read-only files. This leads to privilege escalation because unprivileged processes can inject code into root processes.

Successful exploitation could allow an attacker/hackers with local access to overwrite data in arbitrary read-only files. Attackers can abuse this overwrite flaw to escalate privileges and inject code from unprivileged processes to privileged processes.

Impact on the listed Barco products:

Barco is currently analyzing the impact on our Linux based products. This issue is not applicable for all our Microsoft Windows based systems.
As the investigation continues, information will be updated here. 

ProductStatus
ClickShare (Base Units, Buttons, and Apps) Not affected
XMS CloudNot affected 
XMS Edge

Not affected 

CMGSNot affected 
TransForm N (TFN)Not affected
OpSpaceNot affected 
SecureStream (Discontinued)Not affected
Video Wall Management suite (Cloud)? Not affected
Video Wall Manager (on-prem) Not affected  
Green Barco Wall Control Manager (gBCM)  Not affected  
Infinipix Not affected  
weConnectNot affected
wePresentNot affected
OvertureNot affected

 

Info! Please note that the above article contains preliminary information and will be updated regularly.

External references:

Properties

Last updated Jan 22, 2024