Vulnerability record · CVE-2022-0847 · published 10 March 2022
CVE-2022-0847: Linux kernel pipe buffer flaw allows local privilege escalation
Linux · Linux Kernel
The flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values. An unprivileged local user can exploit this to write to page cache pages backing read-only files, overwriting data and escalating privileges. The flaw is in the Linux kernel and affects multiple distributions and products built on it.
Description
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8, CISA KEV listing, public exploits and very high EPSS make this a high-priority local privilege escalation flaw.
What it is
The flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values. An unprivileged local user can exploit this to write to page cache pages backing read-only files, overwriting data and escalating privileges. The flaw is in the Linux kernel and affects multiple distributions and products built on it.
Impact
An attacker with a local unprivileged account gains the ability to write to read-only file pages in the page cache, which can be used to modify protected files and escalate to root. This breaks file integrity and gives full control of the host.
Attack surface
Reached locally by any unprivileged user on a vulnerable Linux kernel; no authentication beyond a local session and no user interaction are required. The CVSS vector AV:L/PR:L/UI:N confirms local, low-privilege access.
Exploitation
CVE-2022-0847 is in CISA KEV (added 2022-04-25) and public exploit code is referenced, with an EPSS 30-day probability of 0.897. No ransomware campaign use is documented.
What to do
- Apply the Linux kernel update from your distribution vendor (Red Hat, Fedora, SUSE, Siemens, SonicWall, NetApp and others have advisories) as the primary fix.
- If patching cannot be done immediately, restrict local shell access and untrusted local users on affected hosts.
- Monitor vendor advisories for the specific kernel packages and versions in use and track the KEV due date of 2022-05-16.
- Reboot after kernel updates so the fixed kernel is running.
- Consider hardening against local privilege escalation by limiting SUID binaries and local accounts where feasible.
Detection
- Monitor for unexpected writes to read-only files or page cache anomalies on Linux hosts.
- Watch for execution of known Dirty Pipe exploit binaries or scripts from local user directories.
- Alert on local privilege escalation attempts and unusual SUID binary behavior.
- Audit kernel versions against vendor fixed releases and flag unpatched systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-0847 to the Known Exploited Vulnerabilities catalog on 25 April 2022 as "Linux Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 16 May 2022.
Affected products
29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-0847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0847), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.