Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 88.6%; technical severity is CVSS 7.8.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Who should care
- Teams operating Fedora, Kernel, Linux Kernel +27 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Fedora, Kernel, Linux Kernel +27 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Red Hat Security patch Show Bug.cgi
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-665
- Affected versions
- Fedoraproject Fedora (Version 35); Linux Kernel; Linux Linux Kernel (Start Including 5.8, End Excluding 5.10.102 | Start Including 5.15, End Excluding 5.15.25 | Start Including 5.16, End Excluding 5.16.11); Netapp H300e Firmware (Version -); Netapp H300s Firmware (Version -); Netapp H410c Firmware (Version -); Netapp H410s Firmware (Version -); Netapp H500e Firmware (Version -)
- Fixed versions
- Linux Linux Kernel (Fixed from 5.10.102, 5.15.25, 5.16.11); Siemens Scalance Lpe9403 Firmware (Fixed from 2.0)
- Published
- 10 March 2022
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 88.6%
- Signal calculated at 82
External references
- SonicWall Third-party advisory SNWLID 2022 0015
- CISA Government advisory CVE-2022-0847
- Exploit information from packetstormsecurity.com
- Exploit information from packetstormsecurity.com
- Exploit information from packetstormsecurity.com
- Packetstormsecurity Third-party advisory Linux 4.20 KTLS Read Only Write
- Cert Portal Siemens Third-party advisory Ssa 222547.pdf
- Exploit information from dirtypipe.cm4all.com
- Security Netapp Third-party advisory Ntap 20220325 0005