← Back to CVE List
Vulnerability Analysis

CVE-2022-0847

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CISA KEV
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
Temporal Score:-
EPSS:89.06%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2022-04-25
Ransomware Use
Unknown
KEV Due Date
2022-05-16
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
89.063%
EPSS Percentile
99.8th pct
GHSA ID
GitHub Severity
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD