Junglewise Threat Intelligence

CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability

CVE-2022-0847 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-04-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's pipe buffer structure initialization allows an unprivileged local user to write to pages in the page cache backed by read-only files. This vulnerability, known as 'Dirty Pipe', can be exploited to escalate privileges to root.

Affected products

  • Linux Linux Kernel

Timeline

  • 2022-04-25: disclosed
  • 2022-04-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-25: advisory

Related threats