← Back

CVE-2022-0847

nvd nist
Published: Mar 10, 2022Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

Affected (36)

Show all products
1 product
Linux Kernel
1 product
Fedora
12 products
1 product
Ovirt Engine
8 products
H300s Firmware
H500s Firmware
H700s Firmware
H300e Firmware
H500e Firmware
H700e Firmware
H410s Firmware
H410c Firmware
1 product
Scalance Lpe9403 Firmware
1 product
Sma1000 Firmware
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 5.15 to 5.15.25
From 5.16 to 5.16.11
From 5.8 to 5.10.102
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 35
Configuration C
19 vulnerable
Configuration D
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Redhat
Enterprise Linux Eus
Version 8.2
Redhat
Enterprise Linux Eus
Version 8.4
Redhat
Enterprise Linux For Power Little Endian
Version 8.0
Redhat
Enterprise Linux For Power Little Endian Eus
Version 8.2
Redhat
Enterprise Linux For Power Little Endian Eus
Version 8.4
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 4.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.4.10.2
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500s
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700s
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300e
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500e
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700e
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410s
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410c
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Siemens
Scalance Lpe9403
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 12.4.2-02044
Running on/withPlatform Versions
Sonicwall
Sma1000
All versions

References (21)

Source: secalert@redhat.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.