Use of uninitialized resource in Linux kernel - CVE-2022-0847

 

Use of uninitialized resource in Linux kernel - CVE-2022-0847

Published: March 8, 2022 / Updated: July 10, 2023


Vulnerability identifier: #VU61110
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0847
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an uninitialized resources. A local user can overwrite arbitrary file in the page cache, even if the file is read-only, and execute arbitrary code on the system with elevated privileges.

The vulnerability was dubbed Dirty Pipe.


Affected software

Linux kernel
Debian Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Slackware Linux
Ubuntu
Kata Containers
Red Hat Virtualization
OpenShift Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Dell Secure Connect Gateway
Session Smart Router
IBM Spectrum Protect Plus
Red Hat Virtualization Host
Dell EMC NetWorker vProxy
redhat-release-virtualization-host (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel-debug-devel
kernel-doc
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
kernel-headers
kernel-devel
kernel-debug-modules-extra
kernel-debug-modules
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
kernel
bpftool
python3-perf
kernel-modules-internal
python-perf
linux (Debian package)
linux-image-5.13.0-35-generic-lpae (Ubuntu package)
linux-image-5.13.0-35-lowlatency (Ubuntu package)
linux-image-5.13.0-35-generic-64k (Ubuntu package)
linux-image-5.13.0-35-generic (Ubuntu package)
linux-image-generic-64k-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-lowlatency-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-oem-20.04 (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-generic-64k (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-5.13.0-1010-intel (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-5.13.0-1016-kvm (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-aws (Ubuntu package)
linux-image-5.13.0-1017-aws (Ubuntu package)
linux-image-5.13.0-1017-azure (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-5.13.0-1019-gcp (Ubuntu package)
linux-image-5.13.0-1020-raspi (Ubuntu package)
linux-image-5.13.0-1020-raspi-nolpae (Ubuntu package)
linux-image-raspi-nolpae (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-5.13.0-1021-oracle (Ubuntu package)
linux-image-oem-20.04d (Ubuntu package)
linux-image-oem-20.04b (Ubuntu package)
linux-image-oem-20.04c (Ubuntu package)
linux-image-5.14.0-1027-oem (Ubuntu package)
FortiSIEM
FortiAuthenticator
FortiProxy
SonicWall SMA 1000
SCALANCE LPE9403
Migration Toolkit for Containers
linux-image-intel (Ubuntu package)

How to mitigate CVE-2022-0847

Install updates from vendor's website.

Linux kernel - addressed in versions 5.10.102, 5.15.25, 5.16.11
Kata Containers - update to 2.5.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.8, 2.4.3
Dell EMC NetWorker vProxy - update to 4.3.0-20
redhat-release-virtualization-host (Red Hat package) - update to 4.4.10-2.el8ev
OpenShift Virtualization - update to 4.9.4
kernel (Red Hat package) - addressed in versions 4.18.0-147.64.1.el8_1, 4.18.0-193.79.1.el8_2, 4.18.0-305.40.2.el8_4, 4.18.0-348.20.1.el8_5
kernel-rt (Red Hat package) - addressed in versions 4.18.0-193.79.1.rt13.129.el8_2, 4.18.0-305.40.2.rt7.113.el8_4, 4.18.0-348.20.1.rt7.150.el8_5
Dell Secure Connect Gateway - update to 5.12.00.10
FortiSIEM - update to 6.4.1
FortiAuthenticator - addressed in versions 6.3.4, 6.4.2
FortiProxy - update to 7.0.4
SonicWall SMA 1000 - update to 12.4.2-05082
Migration Toolkit for Containers - update to 1.5.4
SCALANCE LPE9403 - update to 2.0
kernel-debug-devel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-doc - update to 4.18.0-348.20.1
perf - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-tools-libs-devel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-tools-libs - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-tools - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-modules-extra - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-modules - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-headers - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-devel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug-modules-extra - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug-modules - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug-core - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-debug - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel-cross-headers - update to 4.18.0-348.20.1
kernel-core - addressed in versions 4.18.0-348.20.1, 4.19.91-26
kernel - addressed in versions 4.18.0-348.20.1, 4.19.91-26
bpftool - addressed in versions 4.18.0-348.20.1, 4.19.91-26
python3-perf - update to 4.19.91-26
kernel-modules-internal - update to 4.19.91-26
python-perf - update to 4.19.91-26
Session Smart Router - addressed in versions 5.4.7, 5.5.3
linux (Debian package) - update to 5.10.92-2
linux-image-5.13.0-35-generic-lpae (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-lowlatency (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic-64k (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-5.13.0-35-generic (Ubuntu package) - update to 5.13.0-35.40~20.04.1
linux-image-generic-64k-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-lpae-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-virtual-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-lowlatency-hwe-20.04 (Ubuntu package) - update to 5.13.0.35.40~20.04.20
linux-image-generic-lpae (Ubuntu package) - update to 5.13.0.35.44
linux-image-oem-20.04 (Ubuntu package) - addressed in versions 5.13.0.35.44, 5.14.0.1027.24
linux-image-lowlatency (Ubuntu package) - update to 5.13.0.35.44
linux-image-generic (Ubuntu package) - update to 5.13.0.35.44
linux-image-generic-64k (Ubuntu package) - update to 5.13.0.35.44
linux-image-virtual (Ubuntu package) - update to 5.13.0.35.44
linux-image-5.13.0-1010-intel (Ubuntu package) - update to 5.13.0-1010.10
linux-image-intel (Ubuntu package) - update to 5.13.0.1010.11
linux-image-kvm (Ubuntu package) - update to 5.13.0.1016.16
linux-image-5.13.0-1016-kvm (Ubuntu package) - update to 5.13.0-1016.17
linux-image-azure (Ubuntu package) - addressed in versions 5.13.0.1017.17, 5.13.0.1017.19~20.04.7
linux-image-aws (Ubuntu package) - addressed in versions 5.13.0.1017.18, 5.13.0.1017.19~20.04.10
linux-image-5.13.0-1017-aws (Ubuntu package) - update to 5.13.0-1017.19~20.04.1
linux-image-5.13.0-1017-azure (Ubuntu package) - update to 5.13.0-1017.19~20.04.1
linux-image-gcp (Ubuntu package) - addressed in versions 5.13.0.1019.17, 5.13.0.1019.23~20.04.1
linux-image-gke (Ubuntu package) - update to 5.13.0.1019.17
linux-image-5.13.0-1019-gcp (Ubuntu package) - update to 5.13.0-1019.23~20.04.1
linux-image-5.13.0-1020-raspi (Ubuntu package) - update to 5.13.0-1020.22
linux-image-5.13.0-1020-raspi-nolpae (Ubuntu package) - update to 5.13.0-1020.22
linux-image-raspi-nolpae (Ubuntu package) - update to 5.13.0.1020.25
linux-image-raspi (Ubuntu package) - update to 5.13.0.1020.25
linux-image-oracle (Ubuntu package) - addressed in versions 5.13.0.1021.21, 5.13.0.1021.26~20.04.1
linux-image-5.13.0-1021-oracle (Ubuntu package) - update to 5.13.0-1021.26~20.04.1
linux-image-oem-20.04d (Ubuntu package) - update to 5.14.0.1027.24
linux-image-oem-20.04b (Ubuntu package) - update to 5.14.0.1027.24
linux-image-oem-20.04c (Ubuntu package) - update to 5.14.0.1027.24
linux-image-5.14.0-1027-oem (Ubuntu package) - update to 5.14.0-1027.30
kernel - update to 6.1.10-15.42
IBM Spectrum Protect Plus - update to 10.1.11

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins