kernel: improper initialization of the "flags" member of the new pipe_buffer
Published Mar 7, 2022 ·Due May 16, 2022
7.8
HIGHCVSS 3.1
EPSS 92.80%
Description
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Linux Kernel 5.17 rc6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- ≥ 5.8 · < 5.10.102
- ≥ 5.15 · < 5.15.25
- ≥ 5.16 · < 5.16.11
Configuration 2
- 35
Configuration 3
- 8.0
- 8.2
- 8.4
- 8.0
- 8.2
- 8.4
- 8.0
- 8.2
- 8.4
- 8
- 8
- 8.2
- 8.4
- 8.2
- 8.4
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
Configuration 4
- n/a
Running on/with
- 8.0
- 8.2
- 8.4
- 8.0
- 8.2
- 8.4
Configuration 5
- 4.0
Running on/with
- 8.0
Configuration 6
- 4.4.10.2
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- < 2.0
Running on/with
- n/a
Configuration 16
- ≤ 12.4.2-02044
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-348.20.1.el8_5
Fixed · RHSA-2022:0825
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-348.20.1.rt7.150.el8_5
Fixed · RHSA-2022:0819
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kernel-0:4.18.0-147.64.1.el8_1
Fixed · RHSA-2022:0823
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-0:4.18.0-193.79.1.el8_2
Fixed · RHSA-2022:0820
Red Hat Enterprise Linux 8.2 Extended Update Support
kernel-rt-0:4.18.0-193.79.1.rt13.129.el8_2
Fixed · RHSA-2022:0821
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.40.2.el8_4
Fixed · RHSA-2022:0831
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.40.2.rt7.113.el8_4
Fixed · RHSA-2022:0822
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.4.10-202203101736_8.5
Fixed · RHSA-2022:0841
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-348.20.1.el8_5 | Fixed | RHSA-2022:0825 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-348.20.1.rt7.150.el8_5 | Fixed | RHSA-2022:0819 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel-0:4.18.0-147.64.1.el8_1 | Fixed | RHSA-2022:0823 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-0:4.18.0-193.79.1.el8_2 | Fixed | RHSA-2022:0820 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-rt-0:4.18.0-193.79.1.rt13.129.el8_2 | Fixed | RHSA-2022:0821 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.40.2.el8_4 | Fixed | RHSA-2022:0831 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.40.2.rt7.113.el8_4 | Fixed | RHSA-2022:0822 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.4.10-202203101736_8.5 | Fixed | RHSA-2022:0841 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. Note that PIPE_BUF_FLAG_CAN_MERGE flag attack vector is not available in Red Hat Enterprise Linux 8 and thus the currently known exploits leveraging this flag do not work. The underlying issue (lack of proper pipe_buffer structure initialization) is still present though and other novel ways leading to successful exploitation cannot be fully ruled out.
Red Hat mitigation
Currently there is no mitigation available for this flaw. Customers should update to fixed packages, once they are available.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Apr 25, 2022
Patch Due
May 16, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (60 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 92.80% (0.92795) | 99.83th | v5 (v2026.06.15) |
| Sep 20, 2026 | 89.72% (0.89721) | 99.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 89.06% (0.89063) | 99.76th | v5 (v2026.06.15) |
| May 11, 2026 | 81.46% (0.81461) | 99.19th | v4 (v2025.03.14) |
| Apr 23, 2026 | 82.68% (0.82683) | 99.24th | v4 (v2025.03.14) |
| Apr 10, 2026 | 81.63% (0.81633) | 99.19th | v4 (v2025.03.14) |
| Feb 18, 2026 | 82.78% (0.82780) | 99.22th | v4 (v2025.03.14) |
| Jan 7, 2026 | 84.14% (0.84135) | 99.28th | v4 (v2025.03.14) |
| Jan 5, 2026 | 82.45% (0.82448) | 99.19th | v4 (v2025.03.14) |
| Jan 1, 2026 | 84.99% (0.84992) | 99.32th | v4 (v2025.03.14) |
| Dec 24, 2025 | 83.44% (0.83439) | 99.24th | v4 (v2025.03.14) |
| Dec 23, 2025 | 84.99% (0.84992) | 99.31th | v4 (v2025.03.14) |
| Nov 21, 2025 | 83.44% (0.83439) | 99.22th | v4 (v2025.03.14) |
| Nov 18, 2025 | 93.75% (0.93746) | 99.90th | v4 (v2025.03.14) |
| Nov 5, 2025 | 84.33% (0.84332) | 99.27th | v4 (v2025.03.14) |
| Nov 4, 2025 | 82.68% (0.82676) | 99.19th | v4 (v2025.03.14) |
| Oct 26, 2025 | 85.65% (0.85646) | 99.33th | v4 (v2025.03.14) |
| Oct 23, 2025 | 86.82% (0.86816) | 99.39th | v4 (v2025.03.14) |
| Oct 18, 2025 | 85.41% (0.85410) | 99.32th | v4 (v2025.03.14) |
| Oct 4, 2025 | 83.91% (0.83910) | 99.26th | v4 (v2025.03.14) |
| Sep 21, 2025 | 82.26% (0.82259) | 99.18th | v4 (v2025.03.14) |
| Sep 17, 2025 | 81.02% (0.81021) | 99.12th | v4 (v2025.03.14) |
| Aug 31, 2025 | 82.65% (0.82650) | 99.19th | v4 (v2025.03.14) |
| Jul 24, 2025 | 84.40% (0.84404) | 99.27th | v4 (v2025.03.14) |
| Jul 23, 2025 | 82.69% (0.82694) | 99.18th | v4 (v2025.03.14) |
| Jul 17, 2025 | 83.73% (0.83725) | 99.23th | v4 (v2025.03.14) |
| Jul 16, 2025 | 81.99% (0.81992) | 99.14th | v4 (v2025.03.14) |
| Jul 9, 2025 | 83.43% (0.83432) | 99.22th | v4 (v2025.03.14) |
| Jun 24, 2025 | 84.65% (0.84653) | 99.27th | v4 (v2025.03.14) |
| Jun 20, 2025 | 83.05% (0.83047) | 99.19th | v4 (v2025.03.14) |
| Jun 15, 2025 | 85.24% (0.85239) | 99.30th | v4 (v2025.03.14) |
| Jun 13, 2025 | 87.08% (0.87081) | 99.39th | v4 (v2025.03.14) |
| Jun 4, 2025 | 84.87% (0.84870) | 99.28th | v4 (v2025.03.14) |
| May 21, 2025 | 83.65% (0.83646) | 99.22th | v4 (v2025.03.14) |
| May 20, 2025 | 86.29% (0.86291) | 99.35th | v4 (v2025.03.14) |
| May 19, 2025 | 83.85% (0.83851) | 99.23th | v4 (v2025.03.14) |
| May 12, 2025 | 85.61% (0.85608) | 99.31th | v4 (v2025.03.14) |
| May 11, 2025 | 86.98% (0.86982) | 99.38th | v4 (v2025.03.14) |
| May 4, 2025 | 83.65% (0.83646) | 99.22th | v4 (v2025.03.14) |
| Apr 22, 2025 | 82.33% (0.82329) | 99.15th | v4 (v2025.03.14) |
| Apr 15, 2025 | 80.63% (0.80632) | 99.06th | v4 (v2025.03.14) |
| Apr 9, 2025 | 87.33% (0.87326) | 99.42th | v4 (v2025.03.14) |
| Mar 19, 2025 | 86.31% (0.86306) | 99.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 87.40% (0.87402) | 99.42th | v4 (v2025.03.14) |
| Dec 17, 2024 | 3.72% (0.03719) | 91.66th | v3 (v2023.03.01) |
| Jul 3, 2024 | 12.09% (0.12091) | 95.41th | v3 (v2023.03.01) |
| Nov 8, 2023 | 7.58% (0.07584) | 93.44th | v3 (v2023.03.01) |
| Jul 9, 2023 | 19.01% (0.19014) | 95.56th | v3 (v2023.03.01) |
| Jul 8, 2023 | 18.75% (0.18745) | 95.53th | v3 (v2023.03.01) |
| May 8, 2023 | 39.66% (0.39665) | 96.68th | v3 (v2023.03.01) |
| Mar 27, 2023 | 7.97% (0.07968) | 93.22th | v3 (v2023.03.01) |
| Mar 7, 2023 | 6.50% (0.06502) | 92.58th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.50% (0.06503) | 91.06th | v2 (v2022.01.01) |
| Nov 15, 2022 | 6.50% (0.06503) | 90.73th | v2 (v2022.01.01) |
| Aug 10, 2022 | 8.24% (0.08242) | 93.17th | v2 (v2022.01.01) |
| Jul 15, 2022 | 8.06% (0.08062) | 92.97th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.50% (0.06503) | 90.18th | v2 (v2022.01.01) |
| Mar 11, 2022 | 6.50% (0.06503) | 78.42th | v2 (v2022.01.01) |
| Mar 9, 2022 | 6.01% (0.06006) | 77.87th | v2 (v2022.01.01) |
| Mar 8, 2022 | 1.41% (0.01412) | 50.81th | v2 (v2022.01.01) |
References (16)
- http://packetstormsecurity.com/files/166229/Dirty-Pipe-Linux-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/166230/Dirty-Pipe-SUID-Binary-Hijack-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/176534/Linux-4.20-KTLS-Read-Only-Write.html Third Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2022-0847 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060795 Issue TrackingPatchThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf Third Party Advisory
- https://dirtypipe.cm4all.com/ ExploitThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/lib/iov_iter.c?id=9d2231c5d74e13b2a0546fee6737ee4446017903
- https://nvd.nist.gov/vuln/detail/CVE-2022-0847
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0015 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220325-0005/ Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0847 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2022-0847
- https://www.suse.com/support/kb/doc/?id=000020603 Third Party Advisory
Change history (0)
No recorded changes yet.