Vulnerability Intelligence Report
Linux Kernel Privilege Escalation Vulnerability
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:89.06%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-665 ↗CWE-665->CWE-281
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| fedoraproject | fedora | 35 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.2, 8.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.2, 8.4 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.2, 8.4 |
| redhat | enterprise_linux_for_real_time | 8 |
| redhat | enterprise_linux_for_real_time_for_nfv | 8 |
| redhat | enterprise_linux_for_real_time_for_nfv_tus | 8.2, 8.4 |
| redhat | enterprise_linux_for_real_time_tus | 8.2, 8.4 |
| redhat | enterprise_linux_server_aus | 8.2, 8.4 |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.1, 8.2, 8.4 |
| redhat | enterprise_linux_server_tus | 8.2, 8.4 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.1, 8.2, 8.4 |
| redhat | codeready_linux_builder | all |
| redhat | virtualization_host | 4.0 |
| ovirt | ovirt-engine | 4.4.10.2 |
| netapp | h300s_firmware | all |
| netapp | h300s | all |
| netapp | h500s_firmware | all |
| netapp | h500s | all |
| netapp | h700s_firmware | all |
| netapp | h700s | all |
| netapp | h300e_firmware | all |
| netapp | h300e | all |
| netapp | h500e_firmware | all |
| netapp | h500e | all |
| netapp | h700e_firmware | all |
| netapp | h700e | all |
| netapp | h410s_firmware | all |
| netapp | h410s | all |
| netapp | h410c_firmware | all |
| netapp | h410c | all |
| siemens | scalance_lpe9403_firmware | all |
| siemens | scalance_lpe9403 | all |
| sonicwall | sma1000_firmware | all |
| sonicwall | sma1000 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
EPSS Score
89.063%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2022-03-03T00:00:00 |
| Published | 2022-03-07T00:00:00 |
| Last Updated | 2025-10-21T23:15:44 |
Community Chatter & Buzz