ID:8097 - Exploit for Use of uninitialized resource in Linux kernel - CVE-2022-0847

 
Main Vulnerability Database Exploits ID:8097 - Exploit for Use of uninitialized resource in Linux kernel - CVE-2022-0847

ID:8097 - Exploit for Use of uninitialized resource in Linux kernel - CVE-2022-0847

Published: June 30, 2022


Vulnerability identifier: #VU61110
Vulnerability risk: Low
CVE-ID: CVE-2022-0847
CWE-ID: CWE-908
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an uninitialized resources. A local user can overwrite arbitrary file in the page cache, even if the file is read-only, and execute arbitrary code on the system with elevated privileges.

The vulnerability was dubbed Dirty Pipe.


Remediation

Install updates from vendor's website.