KEVIntel
7.8
CVSS
High

CVE-2022-0847

PUBLISHED

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and...

Exploited in the wild Low complexity No user interaction
Vendor
Linux
Product
kernel
Published
Mar 07, 2022
EPSS

Description

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

linux cisa metasploit

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-04-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 25, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

cve_2022_0847_dirtypipe

metasploit · Created Unknown

Metasploit module for CVE-2022-0847

h4ckm310n/CVE-2022-0847-eBPF

github · Created 2023-07-06 01:31:01 UTC · 8 stars

An eBPF program to detect attacks on CVE-2022-0847

JlSakuya/CVE-2022-0847-container-escape

github · Created 2023-04-26 13:37:14 UTC · 2 stars

A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.

mutur4/CVE-2022-0847

github · Created 2023-01-24 08:44:32 UTC · 2 stars

Drity Pipe Linux Kernel 1-Day Exploit

ajith737/Dirty-Pipe-CVE-2022-0847-POCs

github · Created 2023-01-04 12:17:12 UTC · 0 stars

DataFox/CVE-2022-0847

github · Created 2022-12-21 16:34:18 UTC · 0 stars

CVE-2022-0847

yoeelingBin/CVE-2022-0847-Container-Escape

github · Created 2022-08-18 03:06:15 UTC · 5 stars

CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

EagleTube/CVE-2022-0847

github · Created 2022-08-13 16:58:40 UTC · 2 stars

Modified dirtypipe script into auto root without have to search a file manually to hijack suid binary.

eduquintanilha/CVE-2022-0847-DirtyPipe-Exploits

github · Created 2022-08-01 14:14:40 UTC · 2 stars

COMPILED

greenhandatsjtu/CVE-2022-0847-Container-Escape

github · Created 2022-06-04 08:31:32 UTC · 32 stars

CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸

VinuKalana/DirtyPipe-CVE-2022-0847

github · Created 2022-05-17 04:23:34 UTC · 2 stars

This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847

tmoneypenny/CVE-2022-0847

github · Created 2022-03-22 03:17:51 UTC · 2 stars

Dirty Pipe - CVE-2022-0847

LudovicPatho/CVE-2022-0847_dirty-pipe

github · Created 2022-03-18 22:51:02 UTC · 8 stars

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

MrP1xel/CVE-2022-0847-dirty-pipe-kernel-checker

github · Created 2022-03-15 11:25:19 UTC · 4 stars

Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847

CYB3RK1D/CVE-2022-0847-POC

github · Created 2022-03-14 13:21:25 UTC · 2 stars

dirtypipe

sa-infinity8888/Dirty-Pipe-CVE-2022-0847

github · Created 2022-03-13 05:51:06 UTC · 3 stars

CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.

AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits

github · Created 2022-03-12 20:57:24 UTC · 597 stars

A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.

arttnba3/CVE-2022-0847

github · Created 2022-03-12 11:31:46 UTC · 6 stars

my personal exploit of CVE-2022-0847(dirty pipe)

chenaotian/CVE-2022-0847

github · Created 2022-03-10 01:27:29 UTC · 25 stars

CVE-2022-0847 POC and Docker and Analysis write up

gyaansastra/CVE-2022-0847

github · Created 2022-03-09 15:44:58 UTC · 2 stars

Dirty Pipe POC

Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit

github · Created 2022-03-09 05:22:20 UTC · 7 stars

Al1ex/CVE-2022-0847

github · Created 2022-03-09 02:47:08 UTC · 80 stars

CVE-2022-0847

dadhee/CVE-2022-0847_DirtyPipeExploit

github · Created 2022-03-09 01:55:04 UTC · 2 stars

A “Dirty Pipe” vulnerability with CVE-2022-0847 and a CVSS score of 7.8 has been identified, affecting Linux Kernel 5.8 and higher. The vulnerability allows attackers to overwrite data in read-only files. Threat actors can exploit this vulnerability to privilege themselves with code injection.

4luc4rdr5290/CVE-2022-0847

github · Created 2022-03-08 20:18:28 UTC · 4 stars

CVE-2022-0847

basharkey/CVE-2022-0847-dirty-pipe-checker

github · Created 2022-03-08 17:13:24 UTC · 67 stars

Bash script to check for CVE-2022-0847 "Dirty Pipe"

puckiestyle/CVE-2022-0847

github · Created 2022-03-08 14:46:21 UTC · 2 stars

knqyf263/CVE-2022-0847

github · Created 2022-03-08 13:48:55 UTC · 47 stars

The Dirty Pipe Vulnerability

cspshivam/CVE-2022-0847-dirty-pipe-exploit

github · Created 2022-03-08 10:40:07 UTC · 1 stars

An exploit for CVE-2022-0847 dirty-pipe vulnerability

ZZ-SOCMAP/CVE-2022-0847

github · Created 2022-03-08 09:10:51 UTC · 58 stars

Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.

si1ent-le/CVE-2022-0847

github · Created 2022-03-08 04:51:02 UTC · 0 stars

CVE-2022-0487

lucksec/CVE-2022-0847

github · Created 2022-03-08 01:17:09 UTC · 1 stars

Arinerron/CVE-2022-0847-DirtyPipe-Exploit

github · Created 2022-03-07 18:55:20 UTC · 1099 stars

A root exploit for CVE-2022-0847 (Dirty Pipe)

r1is/CVE-2022-0847

github · Created 2022-03-07 18:36:50 UTC · 280 stars

CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”

xndpxs/CVE-2022-0847

github · Created 2022-03-07 17:51:02 UTC · 9 stars

Vulnerability in the Linux kernel since 5.8

bbaranoff/CVE-2022-0847

github · Created 2022-03-07 15:50:18 UTC · 49 stars

CVE-2022-0847

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit