A vulnerability was found in Linux Kernel up to 5.10.101/5.15.24/5.16.10 (Operating System) and classified as critical. This issue affects some unknown processing of the component Pipe Handler. Impacted is confidentiality, integrity, and availability.
The weakness was presented 03/08/2022. The advisory is shared at dirtypipe.cm4all.com. The identification of this vulnerability is CVE-2022-0847. The exploitation is known to be easy. The attack may be initiated remotely. Required for exploitation is a simple authentication. Technical details are unknown but a public exploit is available.
Upgrading to version 5.10.102, 5.15.25 or 5.16.11 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at lore.kernel.org. The best possible mitigation is suggested to be upgrading to the latest version.
* POC https://github.com/Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit/blob/main/CVE-2022-0847.gif