Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-0847

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.823
EPSS Ranking 99.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Proposed Action
Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
Ransomware Campaign
Unknown
References
Products affected by CVE-2022-0847


Contact Us

Shodan ® - All rights reserved