[Login to see the link] can someone run this script on a device ? prob something like
adb shell push dpipe.sh /sdcard
adb shell /sdcard/dpipe
also - this exploit can run on android see for example this repo for pixel [Login to see the link]
kernel versions begginning with the number 5 are among those at risk. the bug was introduced with Linux kernel version 5.8 - so can ppl please post here their device name and kernel version (settings > about phone > Software Information > kernel version) so we know which devices are vulnerable?
Edit according to [Login to see the link] blogpost, the dirty pipe vulnerability only exists in android from Android 12 (API 31/Snow Cone) and Higher. I assume that means to the exclusion of flip phones which (to my knowledge) all run considerably lower. nevertheless, it may be worthwhile to check kernel versions and maybe run the above script just to be sure...