CVE-2022-0847 - Design/Logic Flaw
CVE Information
Original CVE data
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Fedoraproject - (1)
Linux - (1)
Netapp - (8)
Ovirt - (1)
Redhat - (16)
Siemens - (1)
Sonicwall - (1)
Basic Analysis
Common vulnerability metrics
Design/Logic Flaw
-
Exploits are available either through exploit packs, Github repos or the world wide web in general.
Vulnerability is referenced under CISA's Known Exploited Vulnerabilities (KEV) catalog. See the KEV Catalog
-
No sightings of the vulnerability within threat reports.
Cybersecurity Frameworks
How the vulnerability maps against various cybersecurity frameworks
Compliance Impact
How the submited vulnerability affects compliance
Web Application Security Frameworks
Applicable if the issue likely affects a web application