CVE-2022-0847General(fedoraproject / codeready_linux_builder)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch fedoraproject codeready_linux_builder systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-16. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-665

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • codeready_linux_builder
  • enterprise_linux
  • enterprise_linux_eus
  • enterprise_linux_for_ibm_z_systems

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 26 mentions across 21 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • General: 17 classified signals
  • Peaked 10d ago at 3 mentions (2026-05-08); latest day: 1
  • 26 total mentions across 21 days

Affected systems

Products
codeready_linux_builderenterprise_linuxenterprise_linux_eusenterprise_linux_for_ibm_z_systemsenterprise_linux_for_ibm_z_systems_eusenterprise_linux_for_power_little_endianenterprise_linux_for_power_little_endian_eusenterprise_linux_for_real_timeenterprise_linux_for_real_time_for_nfventerprise_linux_for_real_time_for_nfv_tus

9 versions affected across 39 products

Deep dive

Activity timeline26 mentions / 21d
01223Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-03-05: 1Mentions · 2026-03-11: 1Mentions · 2026-04-05: 1Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Mentions · 2026-04-16: 1Mentions · 2026-04-25: 1Mentions · 2026-05-01: 2Mentions · 2026-05-08: 3Mentions · 2026-05-09: 1Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-05-22: 2Mentions · 2026-06-01: 1Mentions · 2026-06-05: 1Mentions · 2026-07-25: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-04-25: 1PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-04-25: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-05: 101-2803-0504-0504-0904-2505-0805-1105-1405-2206-0509-23
Signal classification6 categories
General
1765.4%
PoC
311.5%
Patch
27.7%
Active Exploitation
27.7%
False Positive
13.8%
Disclosure
13.8%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-01-281
PoC1
2026-01-291
General1
2026-03-051
PoC1
2026-03-111
General1
2026-04-051
General1
2026-04-081
Patch1
2026-04-091
Active Exploitation1
2026-04-161
General1
2026-04-251
PoC1
2026-05-012
False Positive1General1
2026-05-083
Disclosure1General1Patch1
2026-05-091
General1
2026-05-111
General1
2026-05-121
Active Exploitation1
2026-05-142
General2
2026-05-151
General1
2026-05-222
General2
2026-06-011
General1
2026-06-051
General1
2026-07-251
General1
2026-09-231
General1
Full discourse20 posts
  • hsn今天吃什么@hsn8086k
    General

    2026 Linux 重置密码教程大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The content presents a list of Linux CVEs and their common names, but lacks details on attacks, PoCs, or mitigation information.

    17193111.1K50579.9K
    2.3K followersView on X
  • hsn今天吃什么@hsn8086k
    General

    Linux 重置密码大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300) -PinTheft (CVE-2026-43494)

    Post summary

    The post catalogs Linux password reset methods linked to several CVEs but does not provide any PoC, exploit code, patch information, or evidence of active exploitation.

    43118972036546.3K
    2.3K followersView on X
  • Het Mehta@hetmehtaa
    General

    Them: Linux is most secure OS Me: Yes - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    A casual dialogue lists several Linux kernel CVEs without offering further technical context, patches, or exploitation details.

    566618598272159.8K
    42.2K followersView on X
  • DMNTR Network Solutions 👻 AS204773@weareDMNTRs
    Disclosure

    🚨 Alerta: vulnerabilidad en el kernel de Linux bautizada como "Dirty Frag" (también "Copy Fail 2"). Permite escalada local de privilegios a root. Es de la familia de Dirty Pipe (CVE-2022-0847). Divulgada el 7 de mayo de 2026. 🧵👇 https://x.com/v4bel/status/2052464007857185136

    Post summary

    The tweet announces a newly disclosed local privilege escalation vulnerability in the Linux kernel, dubbed "Dirty Frag" or "Copy Fail 2", part of the Dirty Pipe family (CVE‑2022‑0847), disclosed on May 7, 2026.

    72731095323.3K
    25.8K followersView on X
  • fuzzsociety@fuzzsociety_org
    General

    PWN The Penguin - From The Browser Instructor: @jeppojeps A hands-on primer on modern Linux kernel & glibc exploitation. Every flagship CVE is paired with the primitive its lecture teaches — the exploit is the lesson. All labs escalate to root, verified end-to-end. Curriculum, CVE-2023-32233 CVE-2021-3490 CVE-2022-0847 Support, 24/7 support via Discord — we've run this with a large cohort of students (happy to connect you with a few)., Average response time: under 1 hour., Dedicated DevOps on call for any lab/infra issues., Prereqs: basic x86/x64 asm · Linux kernel basics · the parent primer course.

    Post summary

    The post promotes a teaching course that covers several CVEs but does not supply PoC, exploit code, or technical vulnerability details.

    00014262
    1.2K followersView on X
  • 好奇猫a@acnekot
    General

    2026 Linux 重置密码教程大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The text lists several Linux CVEs as part of a password‑reset tutorial collection, but provides no PoC details, exploit code, patches, or evidence of active exploitation.

    00040351
    2.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-31431 (Dirty Frag/Copy Fail) Linux kernel privilege escalation vulnerability was actively exploited 9+ days before public disclosure. ReversingLabs identified 163 unique samples across ELF binaries, Python scripts, and malicious PyPI packages. Key technical details: • CVE-2026-31431 exploits kernel page-cache manipulation similar to Dirty Pipe (CVE-2022-0847) for local privilege escalation • Earliest malicious sample observed April 29, 2026 - major surge began May 1 with 50+ samples overnight • Shellcode pattern uses compact syscalls: setuid(0), setgid(0), setgroups(0), then execve("/bin/sh") with TERM=xterm • Linux.Trojan.Multiverze family actively adopted the exploit; malicious PyPI wheel "copyfail" distributed via supply chain Attack methodology (MITRE ATT&CK): • T1068: Exploitation for Privilege Escalation via kernel vulnerability • T1548.001: Abuse setuid/setgid mechanisms for root credential normalization • T1195.002: Supply chain compromise through malicious PyPI package distribution • T1059.004/.006: Unix shell and Python interpreter abuse for payload execution DFIR artifacts and detection: • V4bel reference implementation uses distinctive opcode patterns: b06a0f05 (setgid), b0690f05 (setuid), b0740f05 (setgroups) • Co-occurrence of /bin/sh and TERM=xterm strings with syscall patterns provides high-confidence detection • AV detection rates currently 2-17 scanners, indicating signature gap #DFIR_Radar

    Post summary

    The post reports CVE‑2026‑31431 has been actively exploited for local privilege escalation via a kernel page‑cache flaw, with multiple weaponized samples and supply‑chain attacks, but provides no PoC or patch information.

    12100228
    1.5K followersView on X
  • c0deNinja@gotr00t0day
    General

    kernelpwn: A lightweight, fast kernel exploit suggester written in C++ that automatically detects if your Linux kernel is vulnerable to known privilege escalation exploits. These are the vulnerabilities that kernelpwn can detect: 1. Dirty COW (CVE-2016-5195) 2. Dirty Pipe (CVE-2022-0847) 3. GameOver(lay) (CVE-2023-32629) 4. CVE-2024-1086 5. Copy Fail 6. Dirty Frag Github: https://github.com/gotr00t0day/kernelpwned #hacking #hacker #cybersecurity #cplusplus #coding #infosec #linux #linuxkernel #unix #pentesting #ethicalhacking #infosec #programming

    Post summary

    The post advertises a detection tool (kernelpwn) that flags several known kernel privilege escalation CVEs but provides no exploit code, patch, or active exploitation details.

    00020152
    555 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3006 2 - CVE-2022-0847 3 - CVE-2026-6973 4 - CVE-2026-31431 5 - CVE-2026-29014 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A list of five trending CVE identifiers is posted, without additional technical or contextual details.

    00020140
    1.7K followersView on X
  • Mohi@disismohi
    General

    The dataset: CVE-2021-3156 (sudo heap overflow), CVE-2022-0847 (Dirty Pipe), CVE-2023-38545 (curl SOCKS5). Real vulnerable functions from OpenSSL, Linux kernel, cURL.

    Post summary

    The statement lists three CVEs (CVE-2021-3156, CVE-2022-0847, CVE-2023-38545) with basic vulnerability descriptors and affected software, but offers no further detail or actionable information.

    1000047
    63 followersView on X
  • Luis Lescano@luadoles
    General

    - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300) -PinTheft (CVE-2026-43494)

    Post summary

    The entry lists several CVE identifiers with associated names but provides no additional information or context.

    10000294
    31 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-41940 2 - CVE-2026-23918 3 - CVE-2022-0847 4 - CVE-2026-0300 5 - CVE-2026-6973 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet lists five trending CVEs with a link to a dashboard but provides no additional technical, exploit, or mitigation information.

    00010153
    1.7K followersView on X
  • it-learn.io@it_learn_io
    Patch

    Escape #3: Kernel Exploit Container shares the host kernel. Old kernel → container escape CVEs: - CVE-2022-0847 (DirtyPipe) - CVE-2022-0185 (heap overflow) - CVE-2020-14386 (AF_PACKET) Prevention: Patch your host kernel. Always.

    Post summary

    The post lists several old kernel CVEs and stresses that the host kernel should be patched to mitigate container escape risks.

    1000024
    6 followersView on X
  • Tony Mar BRICS Гreenland Remote Access Tool🐀DEWEK@BRICS247
    General

    https://portal.hunt.io/vulnerability/cve/CVE-2022-0847

    Post summary

    The text contains only a link to a CVE-2022-0847 portal page and does not provide explicit details about PoC, exploitation, active use, remediation, or vulnerability specifics.

    0000017
    146 followersView on X
  • みおど@furlingdu
    General

    2026 Linux 重置密码教程大全 - Dirty Cow (CVE-2016-5195) - Dirty Pipe (CVE-2022-0847) - io_uring UAF (CVE-2022-2602) - Copy Fail (CVE-2026-31431) - io_uring ZCRX freelist (CVE-2026-43121) - Dirty Frag (CVE-2026-43284 CVE-2026-43500) - Fragnesia (CVE-2026-46300)

    Post summary

    The post simply lists several Linux CVE identifiers as part of a reset‑password tutorial, providing no further exploit, patch, or impact details.

    00000164
    2.0K followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Patch

    Third page-cache LPE in 4 years: Dirty Pipe (CVE-2022-0847), Copy Fail (CVE-2026-31431), now Dirty Frag. Chains ESP (CVE-2026-43284, in mainline) + RxRPC (CVE-2026-43500, pending). Take the ESP fix today — it breaks the published chain even before RxRPC lands.

    Post summary

    The author lists recent page‑cache LPE exploits (Dirty Pipe, Copy Fail, Dirty Frag) and urges applying the ESP patch immediately to break the chain before the RxRPC vulnerability lands.

    00000157
    34 followersView on X
  • らるる@rarul_extend
    General

    CVE-2026-31431 の spliceを使ってinodeは変更せずにpage cacheだけ変更するって、なんか似たようなの過去にもあったよなぁと思ったら、やっぱり CVE-2022-0847 が類似してると指摘する人がそこそこいた。

    Post summary

    The tweet notes that CVE-2026-31431 modifies page cache via splice without altering the inode, and comments on its similarity to CVE-2022-0847, but no evidence of exploitation or available patches is provided.

    0000090
    108 followersView on X
  • Lyrie.ai@lyrie_ai
    False Positive

    This looks like either misinformation or a poorly sourced claim—CVE-2026-31431 doesn't exist (we're still in 2024), and a 732-byte exploit for universal root across all Linux distros since 2017 would be the security story of the decade. Stick to verified CVEs like Dirty Pipe (CVE-2022-0847) if you want credible Linux privilege escalation info.

    Post summary

    The post debunks CVE‑2026‑31431 as a non‑existent entry and urges readers to focus on verified CVEs like Dirty Pipe.

    0000051
    152 followersView on X
  • Git Rated@GitRated
    PoC

    A new AI review! Arinerron/CVE-2022-0847-DirtyPipe-Exploit ⭐2.7/5.0 This repository is a small, single-purpose proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), derived from Max Kellermann’s original PoC and... https://gitrated.com/Arinerron/CVE-2022-0847-DirtyPipe-Exploit

    Post summary

    The post announces a repository containing a proof‑of‑concept exploit for CVE‑2022‑0847 (Dirty Pipe).

    00000217
    39 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    Dirty Pipe (CVE-2022-0847) was just a rehearsal. The next Linux kernel write bug is already being discussed in private mailing lists. Here's your evergreen playbook to stop chasing CVEs forever. Read more: 👉 https://tinyurl.com/bdfksekx #AlmaLinux https://t.co/0Ilb74UYEL

    Post summary

    The tweet comments on CVE‑2022‑0847 as a rehearsal and hints at a playbook link, but offers no concrete technical info, PoC, exploit, patch, or exploitation evidence.

    0000043
    1.5K followersView on X
CPE platform detail50 entries

50 of 50 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora35--
OSlinuxlinux_kernel---
HWnetapph300e---
OSnetapph300e_firmware---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410c---
OSnetapph410c_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500e---
OSnetapph500e_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph700e---
OSnetapph700e_firmware---
HWnetapph700s---
OSnetapph700s_firmware---
Appovirtovirt-engine4.4.10.2--
Appredhatcodeready_linux_builder---
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux_eus8.2--
OSredhatenterprise_linux_eus8.4--
OSredhatenterprise_linux_for_ibm_z_systems8.0--
OSredhatenterprise_linux_for_ibm_z_systems_eus8.2--
OSredhatenterprise_linux_for_ibm_z_systems_eus8.4--
OSredhatenterprise_linux_for_power_little_endian8.0--
OSredhatenterprise_linux_for_power_little_endian_eus8.2--
OSredhatenterprise_linux_for_power_little_endian_eus8.4--
OSredhatenterprise_linux_for_real_time8--
OSredhatenterprise_linux_for_real_time_for_nfv8--
OSredhatenterprise_linux_for_real_time_for_nfv_tus8.2--
OSredhatenterprise_linux_for_real_time_for_nfv_tus8.4--
OSredhatenterprise_linux_for_real_time_tus8.2--
OSredhatenterprise_linux_for_real_time_tus8.4--
OSredhatenterprise_linux_server_aus8.2--
OSredhatenterprise_linux_server_aus8.4--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.1--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.2--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.4--
OSredhatenterprise_linux_server_tus8.2--
OSredhatenterprise_linux_server_tus8.4--
OSredhatenterprise_linux_server_update_services_for_sap_solutions8.1--
OSredhatenterprise_linux_server_update_services_for_sap_solutions8.2--
OSredhatenterprise_linux_server_update_services_for_sap_solutions8.4--
Appredhatvirtualization_host4.0--
HWsiemensscalance_lpe9403---
OSsiemensscalance_lpe9403_firmware---
HWsonicwallsma1000---
OSsonicwallsma1000_firmware---

Explore more