Database/Kernel, userspace & hypervisor
Linux kernel (pipe): Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, incl
Impact
Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, incl. host binaries from inside a container [KEV]
Who can reach it
Any tenant process in a container
What to do
Livepatchable (all major vendors shipped livepatches); otherwise drain + reboot. Highest-priority historical container-escape primitive
Fleet impact
How widespread
Universal - every kernel 5.8+ before 5.16.11/5.15.25/5.10.102, which was the mainstream range on GPU hosts at the time
Cost to remediate
node-reboot - a kernel fix means a reboot of every GPU host unless the operator runs livepatch/kpatch; either way jobs must be drained first
Why it hits the whole fleet
An unprivileged process in a container overwrites read-only files, and the modification lands on the *host* file (page cache is shared), so a tenant overwrites host SUID binaries and takes the node
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.