7.8

CVE-2022-0847 (Dirty Pipe)

Warnung
Medienbericht
Exploit
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.8 < 5.10.102
Linux ≫ Linux Kernel Version >= 5.15 < 5.15.25
Linux ≫ Linux Kernel Version >= 5.16 < 5.16.11
Fedoraproject ≫ Fedora Version 35
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Virtualization Host Version 4.0
   Redhat ≫ Enterprise Linux Version 8.0
Ovirt ≫ Ovirt-engine Version 4.4.10.2
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Siemens ≫ Scalance Lpe9403 Firmware Version < 2.0
   Siemens ≫ Scalance Lpe9403 Version -
Sonicwall ≫ Sma1000 Firmware Version <= 12.4.2-02044
   Sonicwall ≫ Sma1000 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

25.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Privilege Escalation Vulnerability

Schwachstelle

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 88.61% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.09.2026 23:00
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.08.2026 11:01
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.04.2026 11:39
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0015
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
Third Party Advisory
http://packetstormsecurity.com/files/166229/Dirty-Pipe-Linux-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/166230/Dirty-Pipe-SUID-Binary-Hijack-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/176534/Linux-4.20-KTLS-Read-Only-Write.html
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=2060795
Patch
Third Party Advisory
Issue Tracking
https://dirtypipe.cm4all.com/
Third Party Advisory
Exploit
https://security.netapp.com/advisory/ntap-20220325-0005/
Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020603
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0847
US Government Resource