A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Aug 2024 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2022-03-07T00:00:00
Updated: 2024-08-02T23:40:04.513Z
Reserved: 2022-03-03T00:00:00
Link: CVE-2022-0847
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-10T17:44:57.283
Modified: 2024-11-21T06:39:30.990
Link: CVE-2022-0847
Redhat