A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
CVE-2022-0847
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-04-25), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 7.8
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS
- 99.8%
- KEV
- ⚠ Exploited
Published
March 10, 2022
Last Modified
November 6, 2025
Advisory Details (8)
Auto-updated Jun 3, 2026The Dirty Pipe Vulnerability — The Dirty Pipe Vulnerability documentation
https://dirtypipe.cm4all.com/2060795 – (CVE-2022-0847) CVE-2022-0847 kernel: improper initialization of the "flags" member of the new pipe_buffer
Affected: Red Hat Enterprise Linux 8
https://bugzilla.redhat.com/show_bug.cgi?id=2060795Packet Storm
http://packetstormsecurity.com/files/166258/Dirty-Pipe-Local-Privilege-Escalation.htmlVendor Advisories for CVE-2022-0847(7)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2022:0831Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security update
- RHSA-2022:0825Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
- RHSA-2022:0820Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
- RHSA-2022:0822Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel-rt security update
- RHSA-2022:0823Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security update
- RHSA-2022:0821Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel-rt security and bug fix update
- RHSA-2022:0819Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel-rt security and bug fix update
Patch Availability(10)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | linux-image-unsigned-5.13.0-1010-intel (5.13.0-1010.10) @ focal | 2026-07-22 | ubuntu |
| ubuntu | linux-image-lowlatency (5.13.0.35.44) @ impish | 2026-07-22 | ubuntu |
| redhat | redhat-virtualization-host-0:4.4.10-202203101736_8.5 | 2022-03-14 | redhat |
| redhat | kernel-rt-0:4.18.0-305.40.2.rt7.113.el8_4 | 2022-03-10 | redhat |
| redhat | kernel-0:4.18.0-305.40.2.el8_4 | 2022-03-10 | redhat |
| redhat | kernel-rt-0:4.18.0-348.20.1.rt7.150.el8_5 | 2022-03-10 | redhat |
| redhat | kernel-0:4.18.0-348.20.1.el8_5 | 2022-03-10 | redhat |
| redhat | kernel-0:4.18.0-147.64.1.el8_1 | 2022-03-10 | redhat |
| redhat | kernel-rt-0:4.18.0-193.79.1.rt13.129.el8_2 | 2022-03-10 | redhat |
| redhat | kernel-0:4.18.0-193.79.1.el8_2 | 2022-03-10 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(4)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Microsoft MSRCCVE-2022-08472022-03-11
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
- Red HatRHSA-2022:0841IMPORTANT2022-03-07
RHSA-2022:0841 — Important
- UbuntuUSN-5317-1HIGH
Linux kernel vulnerabilities
- UbuntuUSN-5362-1HIGH
Linux kernel (Intel IOTG) vulnerabilities
Data Freshness Timeline
(refreshed 51× in last 7d / 218× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 407 total refreshes for this CVE.
- 2026-07-23 02:07 UTCEG score recompute
- 2026-07-22 22:41 UTCEG score recompute
- 2026-07-22 22:41 UTCVendor advisory
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 18:52 UTCVendor advisory
- 2026-07-22 15:03 UTCEG score recompute
- 2026-07-22 15:03 UTCVendor advisory
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-22 11:15 UTCVendor advisory
- 2026-07-22 07:28 UTCVendor advisory
- 2026-07-22 03:40 UTCVendor advisory
- 2026-07-21 23:52 UTCVendor advisory
- 2026-07-21 17:54 UTCVendor advisory
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 14:06 UTCVendor advisory
- 2026-07-21 10:19 UTCVendor advisory
- 2026-07-21 06:31 UTCVendor advisory
- 2026-07-21 02:43 UTCVendor advisory
- 2026-07-20 22:55 UTCVendor advisory
- 2026-07-20 19:07 UTCEG score recompute
- 2026-07-20 19:07 UTCVendor advisory
- 2026-07-20 17:05 UTCEPSS rescore
- 2026-07-20 15:20 UTCVendor advisory
- 2026-07-20 11:33 UTCVendor advisory
- 2026-07-20 07:44 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-20 03:56 UTCVendor advisory
- 2026-07-20 00:08 UTCVendor advisory
- 2026-07-19 20:20 UTCVendor advisory
- 2026-07-19 16:30 UTCVendor advisory
- 2026-07-19 12:43 UTCVendor advisory
- 2026-07-19 08:55 UTCVendor advisory
- 2026-07-19 05:07 UTCVendor advisory
- 2026-07-19 01:19 UTCVendor advisory
- 2026-07-18 21:30 UTCVendor advisory
- 2026-07-18 17:42 UTCVendor advisory
- 2026-07-18 13:53 UTCVendor advisory
- 2026-07-18 10:04 UTCVendor advisory
- 2026-07-18 06:16 UTCVendor advisory
- 2026-07-18 02:28 UTCVendor advisory
- 2026-07-17 22:40 UTCVendor advisory
- 2026-07-17 18:52 UTCVendor advisory
- 2026-07-17 15:04 UTCVendor advisory
- 2026-07-17 11:16 UTCVendor advisory
- 2026-07-17 07:27 UTCEG score recompute
- 2026-07-17 07:27 UTCVendor advisory
- 2026-07-17 03:40 UTCVendor advisory
- 2026-07-16 23:51 UTCVendor advisory
- 2026-07-16 20:04 UTCVendor advisory
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 16:15 UTCVendor advisory
- 2026-07-16 12:26 UTCVendor advisory
- 2026-07-16 08:38 UTCVendor advisory
- 2026-07-16 04:50 UTCVendor advisory
- 2026-07-16 01:02 UTCVendor advisory
- 2026-07-15 21:15 UTCVendor advisory
- 2026-07-15 17:26 UTCVendor advisory
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 13:38 UTCVendor advisory
- 2026-07-15 09:50 UTCVendor advisory
- 2026-07-15 06:02 UTCVendor advisory
- 2026-07-15 02:13 UTCVendor advisory
- 2026-07-14 22:25 UTCVendor advisory
- 2026-07-14 18:37 UTCVendor advisory
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 14:50 UTCVendor advisory
- 2026-07-14 11:02 UTCVendor advisory
- 2026-07-14 07:15 UTCVendor advisory
- 2026-07-14 03:28 UTCVendor advisory
- 2026-07-13 23:41 UTCVendor advisory
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 19:53 UTCVendor advisory
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 16:06 UTCVendor advisory
- 2026-07-13 12:16 UTCVendor advisory
- 2026-07-13 08:28 UTCVendor advisory
- 2026-07-13 04:40 UTCVendor advisory
- 2026-07-13 00:53 UTCVendor advisory
- 2026-07-12 21:05 UTCVendor advisory
- 2026-07-12 17:16 UTCVendor advisory
- 2026-07-12 13:29 UTCVendor advisory
- 2026-07-12 09:41 UTCVendor advisory
- 2026-07-12 05:53 UTCVendor advisory
- 2026-07-12 02:06 UTCVendor advisory
- 2026-07-11 22:18 UTCVendor advisory
- 2026-07-11 18:30 UTCVendor advisory
- 2026-07-11 14:43 UTCVendor advisory
- 2026-07-11 10:55 UTCVendor advisory
- 2026-07-11 08:25 UTCEPSS rescore
- 2026-07-11 07:07 UTCVendor advisory
- 2026-07-11 03:18 UTCVendor advisory
- 2026-07-10 23:30 UTCVendor advisory
- 2026-07-10 19:42 UTCVendor advisory
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-10 15:54 UTCVendor advisory
- 2026-07-10 12:06 UTCVendor advisory
- 2026-07-10 08:18 UTCVendor advisory
- 2026-07-10 04:31 UTCVendor advisory
- 2026-07-10 00:42 UTCVendor advisory
- 2026-07-09 20:54 UTCVendor advisory
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCAlexisAhmed/CVE-2022-0847-DirtyPipe-ExploitsFirst seen Mar 12, 2022
A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
Open source ↗ - GitHub PoCAl1ex/CVE-2022-0847First seen Mar 9, 2022
CVE-2022-0847
Open source ↗ - GitHub PoCDataDog/dirtypipe-container-breakout-pocFirst seen Mar 9, 2022
Container Excape PoC for CVE-2022-0847 "DirtyPipe"
Open source ↗ - Exploit-DBEDB-50808First seen Mar 8, 2022
Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)
Open source ↗ - GitHub PoCknqyf263/CVE-2022-0847First seen Mar 8, 2022
The Dirty Pipe Vulnerability
Open source ↗ - GitHub PoCbasharkey/CVE-2022-0847-dirty-pipe-checkerFirst seen Mar 8, 2022
Bash script to check for CVE-2022-0847 "Dirty Pipe"
Open source ↗ - GitHub PoCZZ-SOCMAP/CVE-2022-0847First seen Mar 8, 2022
Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.
Open source ↗ - GitHub PoCfebinrev/dirtypipez-exploitFirst seen Mar 8, 2022
CVE-2022-0847 DirtyPipe Exploit.
Open source ↗ - GitHub PoCr1is/CVE-2022-0847First seen Mar 7, 2022
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
Open source ↗ - GitHub PoCArinerron/CVE-2022-0847-DirtyPipe-ExploitFirst seen Mar 7, 2022
A root exploit for CVE-2022-0847 (Dirty Pipe)
Open source ↗
Frequently asked(6)
What is CVE-2022-0847?
When was CVE-2022-0847 disclosed?
Is CVE-2022-0847 actively exploited?
What is the CVSS score of CVE-2022-0847?
Which products are affected by CVE-2022-0847?
How do I remediate CVE-2022-0847?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2022-0847
Is Your Infrastructure Affected by CVE-2022-0847?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.