← Vulnerability feed

Vulnerability record · CVE-2022-0847 · published 10 March 2022

CVE-2022-0847: Linux kernel pipe buffer flaw allows local privilege escalation

Linux · Linux Kernel

The flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values. An unprivileged local user can exploit this to write to page cache pages backing read-only files, overwriting data and escalating privileges. The flaw is in the Linux kernel and affects multiple distributions and products built on it.

7.8 CVSS 3.1 High CISA KEV since 25 Apr 2022 EPSS 93% · top 0.2% CWE-665 · CWE-665
7.8CVSS 3.1 base score, v2 7.2
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
29Affected product versions listed by NVD
21References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.8, CISA KEV listing, public exploits and very high EPSS make this a high-priority local privilege escalation flaw.

What it is

The flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values. An unprivileged local user can exploit this to write to page cache pages backing read-only files, overwriting data and escalating privileges. The flaw is in the Linux kernel and affects multiple distributions and products built on it.

Impact

An attacker with a local unprivileged account gains the ability to write to read-only file pages in the page cache, which can be used to modify protected files and escalate to root. This breaks file integrity and gives full control of the host.

Attack surface

Reached locally by any unprivileged user on a vulnerable Linux kernel; no authentication beyond a local session and no user interaction are required. The CVSS vector AV:L/PR:L/UI:N confirms local, low-privilege access.

Exploitation

CVE-2022-0847 is in CISA KEV (added 2022-04-25) and public exploit code is referenced, with an EPSS 30-day probability of 0.897. No ransomware campaign use is documented.

What to do

  • Apply the Linux kernel update from your distribution vendor (Red Hat, Fedora, SUSE, Siemens, SonicWall, NetApp and others have advisories) as the primary fix.
  • If patching cannot be done immediately, restrict local shell access and untrusted local users on affected hosts.
  • Monitor vendor advisories for the specific kernel packages and versions in use and track the KEV due date of 2022-05-16.
  • Reboot after kernel updates so the fixed kernel is running.
  • Consider hardening against local privilege escalation by limiting SUID binaries and local accounts where feasible.

Detection

  • Monitor for unexpected writes to read-only files or page cache anomalies on Linux hosts.
  • Watch for execution of known Dirty Pipe exploit binaries or scripts from local user directories.
  • Alert on local privilege escalation attempts and unusual SUID binary behavior.
  • Audit kernel versions against vendor fixed releases and flag unpatched systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-0847 to the Known Exploited Vulnerabilities catalog on 25 April 2022 as "Linux Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 16 May 2022.

Affected products

29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/166229/Dirty-Pipe-Linux-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/166230/Dirty-Pipe-SUID-Binary-Hijack-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/176534/Linux-4.20-KTLS-Read-Only-Write.html Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=2060795 Issue TrackingPatchThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf Third Party Advisory
https://dirtypipe.cm4all.com/ ExploitThird Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0015 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220325-0005/ Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020603 Third Party Advisory
http://packetstormsecurity.com/files/166229/Dirty-Pipe-Linux-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/166230/Dirty-Pipe-SUID-Binary-Hijack-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/176534/Linux-4.20-KTLS-Read-Only-Write.html Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=2060795 Issue TrackingPatchThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf Third Party Advisory
https://dirtypipe.cm4all.com/ ExploitThird Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0015 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220325-0005/ Third Party Advisory
https://www.suse.com/support/kb/doc/?id=000020603 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0847 US Government Resource

Track CVE-2022-0847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-54085AMI MegaRAC SPx BMC authentication bypass via Redfish Host InterfaceAMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authenti…KEVEPSS 61%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed

Source: NIST National Vulnerability Database (record CVE-2022-0847), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.