peter bassill · operator
$ cve CVE-2022-0847 JSON

CVE-2022-0847 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 92.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-16.

Description

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS92.8% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-665
On CISA KEVyes — remediate by 2022-05-16
Public exploityes
Published2022-03-10
Last modified2026-06-17

CISA KEV

NameLinux Kernel Privilege Escalation Vulnerability
Added2022-04-25
Due2022-05-16
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (39)

VendorProduct
fedoraprojectfedora
linuxlinux kernel
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware
ovirtovirt-engine
redhatcodeready linux builder
redhatenterprise linux
redhatenterprise linux eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux for real time
redhatenterprise linux for real time for nfv
redhatenterprise linux for real time for nfv tus
redhatenterprise linux for real time tus
redhatenterprise linux server aus
redhatenterprise linux server for power little endian update services for sap solutions
redhatenterprise linux server tus
redhatenterprise linux server update services for sap solutions
redhatvirtualization host
siemensscalance lpe9403
siemensscalance lpe9403 firmware
sonicwallsma1000
sonicwallsma1000 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD