CVE-2022-0847

Description

A flaw was found in the way the flags member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
83.439

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-5317-1) linux-image-aws_5.13.0.1017.18_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-aws_5.13.0.1017.19~20.04.10_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-gcp_5.13.0.1019.17_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-gcp_5.13.0.1019.23~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-gke_5.13.0.1019.17_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-kvm_5.13.0.1016.16_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-azure_5.13.0.1017.17_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-azure_5.13.0.1017.19~20.04.7_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oracle_5.13.0.1021.21_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oracle_5.13.0.1021.26~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-generic_5.13.0.35.44_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-virtual_5.13.0.35.44_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oem-20.04_5.13.0.35.44_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oem-20.04_5.14.0.1027.24_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-lowlatency_5.13.0.35.44_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oem-20.04b_5.14.0.1027.24_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oem-20.04c_5.14.0.1027.24_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-oem-20.04d_5.14.0.1027.24_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1016-kvm_5.13.0-1016.17_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1017-aws_5.13.0-1017.19_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1017-aws_5.13.0-1017.19~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1019-gcp_5.13.0-1019.23_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1019-gcp_5.13.0-1019.23~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.14.0-1027-oem_5.14.0-1027.30_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1017-azure_5.13.0-1017.19_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1017-azure_5.13.0-1017.19~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-35-generic_5.13.0-35.40_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-35-generic_5.13.0-35.40~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-generic-hwe-20.04_5.13.0.35.40~20.04.20_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-virtual-hwe-20.04_5.13.0.35.40~20.04.20_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1021-oracle_5.13.0-1021.26_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-1021-oracle_5.13.0-1021.26~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-35-lowlatency_5.13.0-35.40_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-5.13.0-35-lowlatency_5.13.0-35.40~20.04.1_amd64.debLinux
Linux kernel (USN-5317-1) linux-image-lowlatency-hwe-20.04_5.13.0.35.40~20.04.20_amd64.debLinux
Kernel-uek update (ELSA-2022-9210) kernel-uek-4.14.35-2047.511.5.6.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2022-9210) kernel-uek-debug-4.14.35-2047.511.5.6.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2022-9210) kernel-uek-debug-devel-4.14.35-2047.511.5.6.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2022-9210) kernel-uek-devel-4.14.35-2047.511.5.6.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2022-9210) kernel-uek-doc-4.14.35-2047.511.5.6.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2022-9210) kernel-uek-tools-4.14.35-2047.511.5.6.el7uek.x86_64.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-abi-stablelists-4.18.0-348.20.1.el8_5.noarch.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-cross-headers-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-debug-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-debug-core-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-debug-modules-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-debug-modules-extra-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-doc-4.18.0-348.20.1.el8_5.noarch.rpmLinux
(RHSA-2022:0825) kernel security, bug fix, and enhancement update kernel-modules-extra-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Bpftool update (ELSA-2022-0825) bpftool-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel update (ELSA-2022-0825) kernel-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-abi-stablelists update (ELSA-2022-0825) kernel-abi-stablelists-4.18.0-348.20.1.el8_5.noarch.rpmLinux
Kernel-core update (ELSA-2022-0825) kernel-core-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-cross-headers update (ELSA-2022-0825) kernel-cross-headers-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-debug update (ELSA-2022-0825) kernel-debug-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-debug-core update (ELSA-2022-0825) kernel-debug-core-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-debug-devel update (ELSA-2022-0825) kernel-debug-devel-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-debug-modules update (ELSA-2022-0825) kernel-debug-modules-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-debug-modules-extra update (ELSA-2022-0825) kernel-debug-modules-extra-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-devel update (ELSA-2022-0825) kernel-devel-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-doc update (ELSA-2022-0825) kernel-doc-4.18.0-348.20.1.el8_5.noarch.rpmLinux
Kernel-headers update (ELSA-2022-0825) kernel-headers-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-modules update (ELSA-2022-0825) kernel-modules-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-modules-extra update (ELSA-2022-0825) kernel-modules-extra-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-tools update (ELSA-2022-0825) kernel-tools-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-tools-libs update (ELSA-2022-0825) kernel-tools-libs-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-tools-libs-devel update (ELSA-2022-0825) kernel-tools-libs-devel-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Perf update (ELSA-2022-0825) perf-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Python3-perf update (ELSA-2022-0825) python3-perf-4.18.0-348.20.1.el8_5.x86_64.rpmLinux
Kernel-uek update (ELSA-2022-9244) kernel-uek-5.4.17-2136.305.5.3.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2022-9244) kernel-uek-debug-5.4.17-2136.305.5.3.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2022-9244) kernel-uek-debug-devel-5.4.17-2136.305.5.3.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2022-9244) kernel-uek-devel-5.4.17-2136.305.5.3.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2022-9244) kernel-uek-doc-5.4.17-2136.305.5.3.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2022-9244) kernel-uek-tools-5.4.17-2136.305.5.3.el7uek.x86_64.rpmLinux
Kernel-uek update (ELSA-2022-9244) kernel-uek-5.4.17-2136.305.5.3.el8uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2022-9244) kernel-uek-debug-5.4.17-2136.305.5.3.el8uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2022-9244) kernel-uek-debug-devel-5.4.17-2136.305.5.3.el8uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2022-9244) kernel-uek-devel-5.4.17-2136.305.5.3.el8uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2022-9244) kernel-uek-doc-5.4.17-2136.305.5.3.el8uek.noarch.rpmLinux
Kernel-uek-container update (ELSA-2022-9245) kernel-uek-container-5.4.17-2136.305.5.3.el8.x86_64.rpmLinux
Kernel-uek-container-debug update (ELSA-2022-9245) kernel-uek-container-debug-5.4.17-2136.305.5.3.el8.x86_64.rpmLinux
Linux kernel for Intel IOTG (USN-5362-1) linux-image-intel_5.13.0.1010.11_amd64.debLinux
Linux kernel for Intel IOTG (USN-5362-1) linux-image-5.13.0-1010-intel_5.13.0-1010.10_amd64.debLinux
Kernel-uek update (ELSA-2022-9313) kernel-uek-4.14.35-2047.512.6.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2022-9313) kernel-uek-debug-4.14.35-2047.512.6.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2022-9313) kernel-uek-debug-devel-4.14.35-2047.512.6.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2022-9313) kernel-uek-devel-4.14.35-2047.512.6.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2022-9313) kernel-uek-doc-4.14.35-2047.512.6.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2022-9313) kernel-uek-tools-4.14.35-2047.512.6.el7uek.x86_64.rpmLinux
Kernel-uek update (ELSA-2022-9367) kernel-uek-4.14.35-2047.513.2.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2022-9367) kernel-uek-debug-4.14.35-2047.513.2.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2022-9367) kernel-uek-debug-devel-4.14.35-2047.513.2.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2022-9367) kernel-uek-devel-4.14.35-2047.513.2.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2022-9367) kernel-uek-doc-4.14.35-2047.513.2.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2022-9367) kernel-uek-tools-4.14.35-2047.513.2.el7uek.x86_64.rpmLinux
kernel Security Update (ALAS-2023-070) kernel-livepatch-6.1.10-15.42-1.0-0.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) bpftool-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) python3-perf-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) perf-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-devel-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-headers-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-libbpf-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-libbpf-devel-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-libbpf-static-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-livepatch-6.1.10-15.42-1.0-0.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-tools-6.1.10-15.42.amzn2023.x86_64.rpmLinux
kernel Security Update (ALAS2023-2023-070) kernel-tools-devel-6.1.10-15.42.amzn2023.x86_64.rpmLinux
Improper Initialization Vulnerability (CVE-2022-0847)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234