A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HFedora Project Fedora
OSFedoraproject35Linux Kernel
OSLinux5.8 – 5.10.102 (excl.)5.15 – 5.15.25 (excl.)5.16 – 5.16.11 (excl.)Netapp H300e
HWNetappall versionsNetapp H300e Firmware
OSNetappall versionsNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H410c
HWNetappall versionsNetapp H410c Firmware
OSNetappall versionsNetapp H410s
HWNetappall versionsNetapp H410s Firmware
OSNetappall versionsNetapp H500e
HWNetappall versionsNetapp H500e Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700e
HWNetappall versionsNetapp H700e Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsOvirt Engine
APPOvirt4.4.10.2Red Hat Codeready Linux Builder
APPRedhatall versionsRed Hat Enterprise Linux
OSRedhat8.0Red Hat Enterprise Linux Eus
OSRedhat8.28.4Red Hat Enterprise Linux For IBM Z Systems
OSRedhat8.0Red Hat Enterprise Linux For IBM Z Systems Eus
OSRedhat8.28.4Red Hat Enterprise Linux For Power Little Endian
OSRedhat8.0Red Hat Enterprise Linux For Power Little Endian Eus
OSRedhat8.28.4Red Hat Enterprise Linux For Real Time
OSRedhat8Red Hat Enterprise Linux For Real Time For Nfv
OSRedhat8Red Hat Enterprise Linux For Real Time For Nfv Tus
OSRedhat8.28.4Red Hat Enterprise Linux For Real Time Tus
OSRedhat8.28.4
CISA KEV — detailsi
- Vendori
- Linux
- Producti
- Kernel
- Added to KEVi
- April 25, 2022
- Remediation deadline (US Federal)i
- May 16, 2022(overdue)
Apply updates per vendor instructions.
Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit