Use of uninitialized resource in Linux kernel - CVE-2022-0847
Published: March 8, 2022 / Updated: July 10, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an uninitialized resources. A local user can overwrite arbitrary file in the page cache, even if the file is read-only, and execute arbitrary code on the system with elevated privileges.
The vulnerability was dubbed Dirty Pipe.
Affected software
Debian Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Slackware Linux
Ubuntu
Kata Containers
Red Hat Virtualization
OpenShift Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Dell Secure Connect Gateway
Session Smart Router
IBM Spectrum Protect Plus
Red Hat Virtualization Host
Dell EMC NetWorker vProxy
redhat-release-virtualization-host (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel-debug-devel
kernel-doc
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-headers
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
python3-perf
kernel-modules-internal
python-perf
linux (Debian package)
linux-image-5.13.0-35-generic-lpae (Ubuntu package)
linux-image-5.13.0-35-lowlatency (Ubuntu package)
linux-image-5.13.0-35-generic-64k (Ubuntu package)
linux-image-5.13.0-35-generic (Ubuntu package)
linux-image-generic-64k-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-lowlatency-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-oem-20.04 (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-generic-64k (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-5.13.0-1010-intel (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-5.13.0-1016-kvm (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-5.13.0-1017-aws (Ubuntu package)
linux-image-5.13.0-1017-azure (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-5.13.0-1019-gcp (Ubuntu package)
linux-image-5.13.0-1020-raspi (Ubuntu package)
linux-image-5.13.0-1020-raspi-nolpae (Ubuntu package)
linux-image-raspi-nolpae (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-5.13.0-1021-oracle (Ubuntu package)
linux-image-oem-20.04d (Ubuntu package)
linux-image-oem-20.04b (Ubuntu package)
linux-image-oem-20.04c (Ubuntu package)
linux-image-5.14.0-1027-oem (Ubuntu package)
FortiSIEM
FortiAuthenticator
FortiProxy
SonicWall SMA 1000
SCALANCE LPE9403
Migration Toolkit for Containers
linux-image-intel (Ubuntu package)
How to mitigate CVE-2022-0847
Kata Containers - update to 2.5.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.8, 2.4.3
Dell EMC NetWorker vProxy - update to 4.3.0-20
redhat-release-virtualization-host (Red Hat package) - update to 4.4.10-2.el8ev
OpenShift Virtualization - update to 4.9.4
kernel (Red Hat package) - addressed in versions 4.18.0-147.64.1.el8_1, 4.18.0-193.79.1.el8_2, 4.18.0-305.40.2.el8_4, 4.18.0-348.20.1.el8_5
kernel-rt (Red Hat package) - addressed in versions 4.18.0-193.79.1.rt13.129.el8_2, 4.18.0-305.40.2.rt7.113.el8_4, 4.18.0-348.20.1.rt7.150.el8_5
Dell Secure Connect Gateway - update to 5.12.00.10
FortiSIEM - update to 6.4.1
FortiAuthenticator - addressed in versions 6.3.4, 6.4.2
FortiProxy - update to 7.0.4
SonicWall SMA 1000 - update to 12.4.2-05082
Migration Toolkit for Containers - update to 1.5.4
SCALANCE LPE9403 - update to 2.0
kernel-debug-devel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-doc - update to 4.18.0-348.20.1
perf - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-tools-libs-devel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-tools-libs - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-tools - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-modules-extra - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-modules - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-headers - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-devel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug-modules-extra - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug-modules - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug-core - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-cross-headers - update to 4.18.0-348.20.1
kernel-core - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
bpftool - addressed in versions 4.18.0-348.20.1, 4.19.91-26
python3-perf - update to 4.19.91-26
kernel-modules-internal - update to 4.19.91-26
python-perf - update to 4.19.91-26
Session Smart Router - addressed in versions 5.4.7, 5.5.3
linux (Debian package) - update to 5.10.92-2
linux-image-5.13.0-35-generic-lpae (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-lowlatency (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic-64k (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-generic-64k-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-lpae-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-virtual-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-lowlatency-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-lpae (Ubuntu package) - update to 5.13.0.35.44
linux-image-oem-20.04 (Ubuntu package) - addressed in versions 5.13.0.35.44, 5.14.0.1027.24
linux-image-lowlatency (Ubuntu package) - update to 5.13.0.35.44
linux-image-generic (Ubuntu package) - update to 5.13.0.35.44
linux-image-generic-64k (Ubuntu package) - update to 5.13.0.35.44
linux-image-virtual (Ubuntu package) - update to 5.13.0.35.44
linux-image-5.13.0-1010-intel (Ubuntu package) - update to 5.13.0-1010.10
linux-image-intel (Ubuntu package) - update to 5.13.0.1010.11
linux-image-kvm (Ubuntu package) - update to 5.13.0.1016.16
linux-image-5.13.0-1016-kvm (Ubuntu package) - update to 5.13.0-1016.17
linux-image-azure (Ubuntu package) - addressed in versions 5.13.0.1017.17, 5.13.0.1017.19~20.04.7
linux-image-aws (Ubuntu package) - addressed in versions 5.13.0.1017.18, 5.13.0.1017.19~20.04.10
linux-image-5.13.0-1017-aws (Ubuntu package) - update to 5.13.0-1017.19~20.04.1
linux-image-5.13.0-1017-azure (Ubuntu package) - update to 5.13.0-1017.19~20.04.1
linux-image-gcp (Ubuntu package) - addressed in versions 5.13.0.1019.17, 5.13.0.1019.23~20.04.1
linux-image-gke (Ubuntu package) - update to 5.13.0.1019.17
linux-image-5.13.0-1019-gcp (Ubuntu package) - update to 5.13.0-1019.23~20.04.1
linux-image-5.13.0-1020-raspi (Ubuntu package) - update to 5.13.0-1020.22
linux-image-5.13.0-1020-raspi-nolpae (Ubuntu package) - update to 5.13.0-1020.22
linux-image-raspi-nolpae (Ubuntu package) - update to 5.13.0.1020.25
linux-image-raspi (Ubuntu package) - update to 5.13.0.1020.25
linux-image-oracle (Ubuntu package) - addressed in versions 5.13.0.1021.21, 5.13.0.1021.26~20.04.1
linux-image-5.13.0-1021-oracle (Ubuntu package) - update to 5.13.0-1021.26~20.04.1
linux-image-oem-20.04d (Ubuntu package) - update to 5.14.0.1027.24
linux-image-oem-20.04b (Ubuntu package) - update to 5.14.0.1027.24
linux-image-oem-20.04c (Ubuntu package) - update to 5.14.0.1027.24
linux-image-5.14.0-1027-oem (Ubuntu package) - update to 5.14.0-1027.30
kernel - update to 6.1.10-15.42
IBM Spectrum Protect Plus - update to 10.1.11
Links to Public Exploits and PoC-codes
- Exploit #9179 - CVE-2022-0847-Exploit-Implementation (Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.) (July 10, 2023)
- Exploit #9125 - dirty-pipe-poc (POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability) (June 22, 2023)
- Exploit #9032 - CVE-2022-0847 (Drity Pipe Linux Kernel 1-Day Exploit) (May 4, 2023)
- Exploit #9011 - CVE-2022-0847-container-escape (A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.) (April 27, 2023)
- Exploit #8996 - cve-2022-0847dirtypipe-exploit () (April 19, 2023)
- Exploit #8691 - CVE-2022-0847 (CVE-2022-0847) (December 22, 2022)
- Exploit #8629 - linux- (修改版CVE-2022-0847) (November 23, 2022)
- Exploit #8621 - CSCI5403_CVE20220847_Detection () (November 21, 2022)
- Exploit #8612 - CVE-2022-0847-DirtyPipe-Exploits (A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.) (November 16, 2022)
- Exploit #8379 - CVE-2022-0847-DirtyPipe-Exploit () (September 19, 2022)
- Exploit #8361 - Dirty-Pipe-Exploits (CVE-2022-0847(Dirty Pipe) vulnerability exploits.) (September 12, 2022)
- Exploit #8309 - CVE-2022-0847-DirtyPipe-Container-Breakout (PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847 ) (August 29, 2022)
- Exploit #8295 - CVE-2022-0847 () (August 24, 2022)
- Exploit #8274 - CVE-2022-0847-Container-Escape (CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸) (August 21, 2022)
- Exploit #8250 - CVE-2022-0847 (Modified dirtypipe script into auto root without have to search a file manually to hijack suid binary.) (August 14, 2022)
- Exploit #8201 - CVE-2022-0847-DirtyPipe-Exploits (COMPILED) (August 1, 2022)
- Exploit #8123 - dpipe (Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)) (July 7, 2022)
- Exploit #8114 - Dirty-Pipe (exp of CVE-2022-0847) (July 5, 2022)
- Exploit #8097 - CBDS_CVE-2022-0847_POC () (June 30, 2022)
- Exploit #8094 - CVE-2022-0847-DirtyPipe-Exploits (A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.) (June 29, 2022)
- Exploit #8038 - CVE-2022-0847-Container-Escape (CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸) (June 15, 2022)
- Exploit #7993 - CVE-2022-0847 (CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸) (June 8, 2022)
- Exploit #7868 - CVE-2022-0847 (CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”) (May 19, 2022)
- Exploit #7815 - Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe) (May 13, 2022)
- Exploit #7782 - Dirty Pipe Local Privilege Escalation via CVE-2022-0847 (May 12, 2022)
- Exploit #7663 - linux-privilege-escalation (Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability) (April 18, 2022)
- Exploit #7654 - CVE-2022-0847-L-nux-PrivEsc () (April 15, 2022)
- Exploit #7603 - CVE-2022-0847_dirty-pipe (Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)) (April 5, 2022)
- Exploit #7584 - CVE-2022-0847 (Linux “Dirty Pipe” vulnerability gives unprivileged users root access) (April 3, 2022)
- Exploit #7527 - pwncat_dirtypipe (pwncat module that automatically exploits CVE-2022-0847 (dirtypipe)) (March 21, 2022)
- Exploit #7524 - CVE-2022-0847 (Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)) (March 20, 2022)
- Exploit #7517 - CVE-2022-0847_DirtyPipe_Exploits (A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.) (March 17, 2022)
- Exploit #7506 - DirtyPIPE-CVE-2022-0847 () (March 16, 2022)
- Exploit #7505 - CVE-2022-0847-DirtyPipe-Exploits () (March 16, 2022)
- Exploit #7501 - CVE-2022-0847 () (March 15, 2022)
- Exploit #7499 - dirty-pipe-poc (CVE-2022-0847 POC) (March 15, 2022)
- Exploit #7498 - CVE-2022-0847-POC (dirtypipe) (March 15, 2022)
- Exploit #7497 - CVE-2022-0847 (dirtypipe) (March 15, 2022)
- Exploit #7491 - cve_2022_0847_shellcode (Implementation of CVE-2022-0847 as a shellcode) (March 15, 2022)
- Exploit #7490 - DirtyPipePython (A Python-based DirtyPipe (CVE-2022-0847) POC to pop a root shell) (March 14, 2022)
- Exploit #7488 - CVE-2022-0847 (my personal exploit of CVE-2022-0847(dirty pipe)) (March 14, 2022)
- Exploit #7481 - Dirty-Pipe-CVE-2022-0847 (CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.) (March 14, 2022)
- Exploit #7479 - CVE-2022-0847-DirtyPipe-Exploits (A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.) (March 14, 2022)
- Exploit #7478 - CVE-2022-0847 (CVE-2022-0847 POC and Docker and Analysis write up) (March 10, 2022)
- Exploit #7476 - CVE-2022-0847-Linux () (March 10, 2022)
- Exploit #7474 - CVE-2022-0847-DirtyPipe-Exploit (CVE-2022-0847-DirtyPipe-Exploit) (March 10, 2022)
- Exploit #7472 - dirtyPipe-automaticRoot (CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.) (March 10, 2022)
- Exploit #7468 - CVE-2022-0847 (A root exploit for CVE-2022-0847 (Dirty Pipe)) (March 10, 2022)
- Exploit #7467 - CVE-2022-0847-DirtyPipe-Exploit () (March 9, 2022)
- Exploit #7466 - cve-2022-0847dirtypipe-exploit () (March 9, 2022)
- Exploit #7465 - pentestblog-CVE-2022-0847 () (March 9, 2022)
- Exploit #7464 - CVE-2022-0847 (Dirty Pipe POC) (March 9, 2022)
- Exploit #7463 - CVE-2022-0847 () (March 9, 2022)
- Exploit #7461 - CVE-2022-0847-DirtyPipe () (March 9, 2022)
- Exploit #7459 - CVE-2022-0847_DirtyPipeExploit (A “Dirty Pipe” vulnerability with CVE-2022-0847 and a CVSS score of 7.8 has been identified, affecting Linux Kernel 5.8 and higher. The vulnerability allows attackers to overwrite data in read-only files. Threat actors can (March 9, 2022)
- Exploit #7458 - CVE-2022-0847 (CVE-2022-0847) (March 9, 2022)
- Exploit #7456 - CVE-2022-0847 (CVE-2022-0487) (March 8, 2022)
- Exploit #7455 - CVE-2022-0847-DirtyPipe-Exploit () (March 8, 2022)
- Exploit #7454 - CVE-2022-0847-DirtyPipe-Exploit (A root exploit for CVE-2022-0847 (Dirty Pipe)) (March 8, 2022)
- Exploit #7453 - CVE-2022-0847 () (March 8, 2022)
- Exploit #7451 - CVE-2022-0847 (Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.) (March 8, 2022)
- Exploit #7450 - CVE-2022-0847-dirty-pipe-exploit (An exploit for CVE-2022-0847 dirty-pipe vulnerability) (March 8, 2022)
- Exploit #7449 - CVE_2022_0847 (CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability) (March 8, 2022)
- Exploit #7448 - CVE-2022-0847-Docker (Docker exploit) (March 8, 2022)
- Exploit #7446 - CVE-2022-0847-dirty-pipe-checker (Bash script to check for CVE-2022-0847 "Dirty Pipe") (March 8, 2022)
- Exploit #7445 - CVE-2022-0847 (CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”) (March 8, 2022)
- Exploit #7444 - cve-2022-0847dirtypipe-exploit () (March 8, 2022)
- Exploit #7443 - CVE-2022-0847 (CVE-2022-0847) (March 8, 2022)
- Exploit #7441 - CVE-2022-0847 () (March 8, 2022)
- Exploit #7440 - CVE-2022-0847 (CVE-2022-0847) (March 8, 2022)
- Exploit #7439 - Dirty-Pipe (CVE-2022-0847 exploit one liner) (March 8, 2022)
- Exploit #7437 - dirtypipez-exploit (CVE-2022-0847 DirtyPipe Exploit.) (March 8, 2022)
- Exploit #7436 - dirty-pipe (Implementation of Max Kellermann's exploit for CVE-2022-0847) (March 8, 2022)
- Exploit #7435 - CVE-2022-0847 (Vulnerability in the Linux kernel since 5.8) (March 8, 2022)
- Exploit #7434 - CVE-2022-0847 (The Dirty Pipe Vulnerability) (March 8, 2022)
External References
Related Security Bulletins
- Privilege escalation in Linux kernel
- Red Hat Enterprise Linux for Real Time 8.4 update for kernel-rt
- Red Hat Enterprise Linux 8.4 update for kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 8.2 update for kernel
- Red Hat Enterprise Linux for Real Time 8.2 update for kernel-rt
- Red Hat Enterprise Linux 8.1 update for kernel
- Red Hat Enterprise Linux 8 update for kernel
- Amazon Linux AMI update for kernel
- Slackware Linux update for Slackware 15.0 kernel
- Multiple vulnerabilities in Red Hat Virtualization
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in Dell EMC NetWorker vProxy
- Multiple vulnerabilities in Siemens SCALANCE LPE9403
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Debian update for linux
- Privilege escalation in SonicWall SMA 1000
- Privilege escalation in kata-containers
- Multiple vulnerabilities in OpenShift Virtualization 4.9
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Ubuntu update for linux
- Fortinet products update for Linux kernel
- Amazon Linux AMI update for kernel
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Ubuntu update for linux-intel-5.13
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Anolis OS update for kernel
- Anolis OS update for kernel(ANCK)4.19
- Anolis OS update for kernel