← Back to CVE List
Vulnerability Intelligence Report
Linux Kernel Privilege Escalation Vulnerability

CVE-2022-0847

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:89.06%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-665 ↗CWE-665->CWE-281

Affected Products & Versions

Vendor Product Affected Versions
linux linux_kernel all
fedoraproject fedora 35
redhat enterprise_linux 8.0
redhat enterprise_linux_eus 8.2, 8.4
redhat enterprise_linux_for_ibm_z_systems 8.0
redhat enterprise_linux_for_ibm_z_systems_eus 8.2, 8.4
redhat enterprise_linux_for_power_little_endian 8.0
redhat enterprise_linux_for_power_little_endian_eus 8.2, 8.4
redhat enterprise_linux_for_real_time 8
redhat enterprise_linux_for_real_time_for_nfv 8
redhat enterprise_linux_for_real_time_for_nfv_tus 8.2, 8.4
redhat enterprise_linux_for_real_time_tus 8.2, 8.4
redhat enterprise_linux_server_aus 8.2, 8.4
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.1, 8.2, 8.4
redhat enterprise_linux_server_tus 8.2, 8.4
redhat enterprise_linux_server_update_services_for_sap_solutions 8.1, 8.2, 8.4
redhat codeready_linux_builder all
redhat virtualization_host 4.0
ovirt ovirt-engine 4.4.10.2
netapp h300s_firmware all
netapp h300s all
netapp h500s_firmware all
netapp h500s all
netapp h700s_firmware all
netapp h700s all
netapp h300e_firmware all
netapp h300e all
netapp h500e_firmware all
netapp h500e all
netapp h700e_firmware all
netapp h700e all
netapp h410s_firmware all
netapp h410s all
netapp h410c_firmware all
netapp h410c all
siemens scalance_lpe9403_firmware all
siemens scalance_lpe9403 all
sonicwall sma1000_firmware all
sonicwall sma1000 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
89.063%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2022-03-03T00:00:00
Published2022-03-07T00:00:00
Last Updated2025-10-21T23:15:44

LINK COPIED TO CLIPBOARD