Skip to main content

CVE detail

CVE-2022-0847

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CVSS 7.8 · HighBuzz score 76.3KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 76.3

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 29.4 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 5.9
Mention score
29.4
18 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
5.9
1 repos · best confidence 0.99
Best PoC traction
2
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
18 source links · newest first
  • y that cloud providers and enterprises rely on to isolate sensitive processes on servers. The vulnerability, tracked as CVE-2026-53359 , stems from a use-after-free memory bug in the shadow MMU emulation of KVM on x86 CPU architecture. According to Hyunwoo Kim , the researcher who discovered it, the flaw has been present in the Linux kernel code for th

    newswww.csoonline.comJul 7, 2026, 9:53 PM
  • A newly disclosed Linux privilege escalation issue dubbed “Dirty Frag” is giving attackers a cleaner path to post-compromise escalation to root privileges. According to Microsoft, a couple of vulnerabilities constituting the issue, affecting Linux kernel networking and memory-fragment handling components, are already seeing active exploitation in the wild. The exploitation attempts look indistinguishable from the […]

    newswww.csoonline.comMay 11, 2026, 12:01 PM
  • CSOs must ensure their Linux-based systems block unauthorized privilege escalation until distros release patches to plug a serious kernel vulnerability affecting all Linux distributions shipped since 2017. Until fixes are available for what’s been dubbed the Copy Fail logic bug (CVE-2026-31431), which lets users easily obtain root access, there isn’t much CSOs can do, says […]

    newswww.csoonline.comMay 1, 2026, 1:14 AM
  • In 2024, nation-state cyber activity was off the charts, with Chinese, Russian, and Iranian actors leading the charge. Their campaigns weren’t just relentless — they were innovative, using a crafty mix of Tactics, Techniques, and Procedures (TTPs) to gain footholds, stay hidden, and spy-like pros. “There was definitely a continued and noted uptick in nation-state […]

    newswww.csoonline.comDec 25, 2024, 6:00 AM
  • An espionage campaign suspected of links to Pakistan is using a novel approach to operate malware within infected Indian government systems, according to research by Volexity. The threat actors — tracked as UTA0137 — use emojis on the messaging service Discord for C2 communications as a technique to evade text-based detection. “Volexity assesses with high […]

    newswww.csoonline.comJun 17, 2024, 11:20 AM
  • Security researchers at Cisco Talos and Volexity flag two Pakistani espionage campaigns targeting Indian government entities.

    newswww.securityweek.comJun 14, 2024, 2:04 PM
  • A critical vulnerability in Fortinet’s FortiPresence data analytics solution leads to remote, unauthenticated access to Redis and MongoDB instances.

    newswww.securityweek.comApr 12, 2023, 2:03 PM
  • Pwning the all Google phone with a non-Google bugGitHub Security Lab

    It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.

    vendorgithub.blogJan 23, 2023, 3:05 PM
  • Academic researchers from Northwestern University have shared details on ‘DirtyCred’, a previously unknown privilege escalation vulnerability affecting the Linux kernel.

    newswww.securityweek.comAug 23, 2022, 12:35 PM
  • Researchers shared details of an eight-year-old flaw dubbed DirtyCred, defined as nasty as Dirty Pipe, in the Linux kernel. Researchers from Northwestern University (Zhenpeng Lin | PhD Student,Yuhang Wu | PhD Student, Xinyu Xing | Associate Professor) disclosed an eight-year-old security vulnerability in the Linux kernel, dubbed DirtyCred, which they defined “as nasty as Dirty Pipe.” The Dirty Pipe flaw, tracked […]

    newssecurityaffairs.comAug 22, 2022, 5:50 PM
  • Metasploit is the world’s most used penetration testing framework. It helps security teams verify vulnerabilities, manage security assessments, and improve security awareness. Metasploit 6.2.0 is now available. It includes 138 new modules, 148 enhancements and features, improvements, and 156 bug fixes. “Our continued focus for Metasploit is on on adding support for modern attacks so the community can highlight risk and test security controls for paths that attackers use regularly. Metasploit 6.2.0 continued this theme … More →

    newswww.helpnetsecurity.comJun 13, 2022, 12:14 PM
  • Microsoft has unearthed two security vulnerabilities (CVE-2022-29799, CVE-2022-29800) in the networkd-dispatcher daemon that may be exploited by attackers to gain root on many Linux endpoints, allowing them to deploy backdoors, malware, ransomware, or perform other malicious actions. About the vulnerabilities (CVE-2022-29799, CVE-2022-29800) CVE-2022-29799 is a directory traversal bug; CVE-2022-29800 is a time-of-check-time-of-use (TOCTOU) race condition that could allow an attacker to replace scripts that networkd-dispatcher (the vulnerable systemd unit) believes to be owned by root … More →

    newswww.helpnetsecurity.comApr 27, 2022, 10:44 AM
  • Taiwanese vendor QNAP warns most of its NAS devices are impacted by high severity Linux vulnerability dubbed ‘Dirty Pipe.’ Taiwanese hardware vendor QNAP warns most of its Network Attached Storage (NAS) devices are impacted by the recently discovered Linux vulnerability ‘Dirty Pipe.’ An attacker with local access can exploit the high-severity vulnerability Dirty Pipe to […]

    newssecurityaffairs.comMar 15, 2022, 11:32 AM
  • 14th March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 14th March, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has analyzed the Conti Ransomware gang’s chat leaks and revealed insights on the group’s Hi-tech company type of management, with physical offices, HR & finance departments and more. CPR […]

    vendorresearch.checkpoint.comMar 14, 2022, 3:48 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Mozilla fixes Firefox zero-days exploited in the wild (CVE-2022-26485, CVE-2022-26486) Mozilla has released an out-of-band security update for Firefox, Firefox Focus, and Thunderbird, fixing two critical vulnerabilities (CVE-2022-26485, CVE-2022-26486) exploited by attackers in the wild. Easily exploitable Linux bug gives root access to attackers (CVE-2022-0847) An easily exploitable vulnerability (CVE-2022-0847) in the Linux kernel can be used by local unprivileged users … More →

    newswww.helpnetsecurity.comMar 13, 2022, 9:00 AM
  • The dangerous Linux privilege escalation flaw dubbed Dirty Pipe that was recently disclosed could also impact applications and systems that use containerization through tools such as Docker, researchers warn. This follows a different privilege escalation vulnerability that was patched last week and could lead to container escapes. Dirty Pipe “could enable an attacker to effectively […]

    newswww.csoonline.comMar 10, 2022, 12:17 PM
  • An easily exploitable vulnerability (CVE-2022-0847) in the Linux kernel can be used by local unprivileged users to gain root privileges on vulnerable systems by taking advantage of already public exploits. Discovered by security researcher Max Kellermann, the flaw – which he dubbed Dirty Pipe, due to its similarity to the Dirty Cow flaw – has already been patched in the Linux kernel and the Android kernel. Affected Linux distributions are in the process of pushing … More →

    newswww.helpnetsecurity.comMar 8, 2022, 9:40 AM
  • Dirty Pipe is a Linux vulnerability, tracked as CVE-2022-0847, that can allow local users to gain root privileges on all major distros. Security expert Max Kellermann discovered a Linux flaw, dubbed Dirty Pipe and tracked as CVE-2022-0847, that can allow local users to gain root privileges on all major distros. The vulnerability affects Linux Kernel […]

    newssecurityaffairs.comMar 8, 2022, 7:53 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 2 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence