7.8
CVE-2022-0847 (Dirty Pipe)
- EPSS 88.61%
- Veröffentlicht 10.03.2022 17:44:57
- Zuletzt bearbeitet 06.11.2025 14:50:37
- Erkennungen
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.8 < 5.10.102
Linux ≫ Linux Kernel Version >= 5.15 < 5.15.25
Linux ≫ Linux Kernel Version >= 5.16 < 5.16.11
Fedoraproject ≫ Fedora Version 35
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.2
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.2
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Enterprise Linux For Real Time Version 8
Redhat ≫ Enterprise Linux For Real Time For Nfv Version 8
Redhat ≫ Enterprise Linux For Real Time For Nfv Tus Version 8.2
Redhat ≫ Enterprise Linux For Real Time For Nfv Tus Version 8.4
Redhat ≫ Enterprise Linux For Real Time Tus Version 8.2
Redhat ≫ Enterprise Linux For Real Time Tus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.1
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.2
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Codeready Linux Builder Version -
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.2
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.2
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Virtualization Host Version 4.0
Ovirt ≫ Ovirt-engine Version 4.4.10.2
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H300e Firmware Version -
Netapp ≫ H500e Firmware Version -
Netapp ≫ H700e Firmware Version -
Netapp ≫ H410s Firmware Version -
Netapp ≫ H410c Firmware Version -
Siemens ≫ Scalance Lpe9403 Firmware Version < 2.0
Sonicwall ≫ Sma1000 Firmware Version <= 12.4.2-02044
VulnDex Vulnerability Enrichment
25.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Linux Kernel Privilege Escalation Vulnerability
SchwachstelleLinux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 88.61% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-665 Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0015
https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
http://packetstormsecurity.com/files/166229/Dirty-Pipe-Linux-Privilege-Escalation.html
http://packetstormsecurity.com/files/166230/Dirty-Pipe-SUID-Binary-Hijack-Privilege-Escalation.html
http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.html
http://packetstormsecurity.com/files/176534/Linux-4.20-KTLS-Read-Only-Write.html
https://bugzilla.redhat.com/show_bug.cgi?id=2060795
https://dirtypipe.cm4all.com/
https://security.netapp.com/advisory/ntap-20220325-0005/
https://www.suse.com/support/kb/doc/?id=000020603
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0847