From the source
As with all important enough vulnerabilities, this one has a catchy name: Dirty Pipe (no logo, though).
This blogpost attempts to explain how that vulnerability impacted Replit.
The good news is that as far as we know, there weren't any successful exploitations of it!
That article linked above has the full explanation and is definitely worth the read because it narrates the journey from discovery to fix.
In case you're in a hurry, the short description of that vulnerability is that it allowed any user to temporarily overwrite any file in the filesystem, without requiring any write permissions to do so.
Temporarily because it didn't actually change the file, just the in-memory page cache, so if the kernel was under any sort of memory pressure, those changes would go away.
There were a few more restrictions (mostly about the position, alignment, and length of the write), but other than that this allowed the attacker to make all sorts of very scary modifications to the system.
…





