🛡️ CVE-2022-0847
🟠 CVSS 7.8 — High ✅ No Known Exploit NVD
7.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

Details

Severity High
CVSS Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2022-05-01
Updated 2026-06-13
Modified 2026-06-12

Affected Packages

Software From version Fixed in
:linux-kernel: :0 :2022-05-05
codeready-linux-builder
enterprise-linux
enterprise-linux-eus
enterprise-linux-for-ibm-z-systems
enterprise-linux-for-ibm-z-systems-eus
enterprise-linux-for-power-little-endian
enterprise-linux-for-power-little-endian-eus
enterprise-linux-for-real-time
enterprise-linux-for-real-time-for-nfv
enterprise-linux-for-real-time-for-nfv-tus
enterprise-linux-for-real-time-tus
enterprise-linux-server-aus
enterprise-linux-server-for-power-little-endian-update-services-for-sap-solutions
enterprise-linux-server-tus
enterprise-linux-server-update-services-for-sap-solutions
fedora
h300e-firmware
h300s-firmware
h410c-firmware
h410s-firmware
h500e-firmware
h500s-firmware
h700e-firmware
h700s-firmware
linux-kernel 5.16 5.16.11
ovirt-engine
scalance-lpe9403-firmware 2.0
sma1000-firmware 12.4.2-02044
virtualization-host

Similar Threats

Exploit Protection

Help block exploit attempts

BotEraser is designed to detect and help reduce malicious bot traffic that may target known vulnerabilities on your site.

Try BotEraser Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.