Linux Kernel Privilege Escalation Vulnerability

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

Published 9 Sep 2026Updated 9 Sep 2026345 sources
CVSS 7.8 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

Affected versions

Kernel: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 50808Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)Lance Biggerstaff2022-03-08VerifiedPoC-in-GitHub · bbaranoff/CVE-2022-0847CVE-2022-0847★ 50bbaranoff2022-03-07CandidatePoC-in-GitHub · xndpxs/CVE-2022-0847Vulnerability in the Linux kernel since 5.8★ 9xndpxs2022-03-07CandidatePoC-in-GitHub · r1is/CVE-2022-0847CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”★ 282r1is2022-03-07CandidatePoC-in-GitHub · Arinerron/CVE-2022-0847-DirtyPipe-ExploitA root exploit for CVE-2022-0847 (Dirty Pipe)★ 1133Arinerron2022-03-07CandidatePoC-in-GitHub · crowsec-edtech/Dirty-PipeCVE-2022-0847 exploit one liner★ 10crowsec-edtech2022-03-07CandidatePoC-in-GitHub · lucksec/CVE-2022-0847★ 1lucksec2022-03-08CandidatePoC-in-GitHub · si1ent-le/CVE-2022-0847CVE-2022-0487★ 0si1ent-le2022-03-08CandidatePoC-in-GitHub · bohr777/cve-2022-0847dirtypipe-exploit★ 0bohr7772022-03-08CandidatePoC-in-GitHub · ZZ-SOCMAP/CVE-2022-0847Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.★ 58ZZ-SOCMAP2022-03-08CandidatePoC-in-GitHub · cspshivam/CVE-2022-0847-dirty-pipe-exploitAn exploit for CVE-2022-0847 dirty-pipe vulnerability★ 2cspshivam2022-03-08CandidatePoC-in-GitHub · febinrev/dirtypipez-exploitCVE-2022-0847 DirtyPipe Exploit.★ 49febinrev2022-03-08CandidatePoC-in-GitHub · ahrixia/CVE_2022_0847CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability★ 21ahrixia2022-03-08CandidatePoC-in-GitHub · knqyf263/CVE-2022-0847The Dirty Pipe Vulnerability★ 46knqyf2632022-03-08CandidatePoC-in-GitHub · puckiestyle/CVE-2022-0847★ 2puckiestyle2022-03-08CandidatePoC-in-GitHub · 0xIronGoat/dirty-pipeImplementation of Max Kellermann's exploit for CVE-2022-0847★ 140xIronGoat2022-03-08CandidatePoC-in-GitHub · ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit★ 1ITMarcin22112022-03-08CandidatePoC-in-GitHub · mrchucu1/CVE-2022-0847-DockerDocker exploit★ 1mrchucu12022-03-08CandidatePoC-in-GitHub · basharkey/CVE-2022-0847-dirty-pipe-checkerBash script to check for CVE-2022-0847 "Dirty Pipe"★ 71basharkey2022-03-08CandidatePoC-in-GitHub · 4luc4rdr5290/CVE-2022-0847CVE-2022-0847★ 64luc4rdr52902022-03-08CandidatePoC-in-GitHub · dadhee/CVE-2022-0847_DirtyPipeExploitA “Dirty Pipe” vulnerability with CVE-2022-0847 and a CVSS score of 7.8 has been identified, affecting Linux Kernel 5.8 and higher. The vulnerability allows attackers to overwrite data in read-only files. Threat actors can exploit this vulnerability to privilege themselves with code injection.★ 2dadhee2022-03-09CandidatePoC-in-GitHub · Greetdawn/CVE-2022-0847-DirtyPipe★ 0Greetdawn2022-03-09CandidatePoC-in-GitHub · Al1ex/CVE-2022-0847CVE-2022-0847★ 91Al1ex2022-03-09CandidatePoC-in-GitHub · Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit★ 6Mustafa19862022-03-09CandidatePoC-in-GitHub · nanaao/Dirtypipe-exploitDirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn. a root shell. (and attempts to restore the damaged binary as well)★ 0nanaao2022-03-09CandidatePoC-in-GitHub · AyoubNajim/cve-2022-0847dirtypipe-exploit★ 0AyoubNajim2022-03-09CandidatePoC-in-GitHub · pentestblogin/pentestblog-CVE-2022-0847★ 0pentestblogin2022-03-09CandidatePoC-in-GitHub · gyaansastra/CVE-2022-0847Dirty Pipe POC★ 3gyaansastra2022-03-09CandidatePoC-in-GitHub · DataDog/dirtypipe-container-breakout-pocContainer Excape PoC for CVE-2022-0847 "DirtyPipe"★ 77DataDog2022-03-09CandidatePoC-in-GitHub · babyshen/CVE-2022-0847A root exploit for CVE-2022-0847 (Dirty Pipe)★ 0babyshen2022-03-10CandidatePoC-in-GitHub · edsonjt81/CVE-2022-0847-Linux★ 0edsonjt812022-03-10CandidatePoC-in-GitHub · chenaotian/CVE-2022-0847CVE-2022-0847 POC and Docker and Analysis write up★ 25chenaotian2022-03-10CandidatePoC-in-GitHub · V0WKeep3r/CVE-2022-0847-DirtyPipe-ExploitCVE-2022-0847-DirtyPipe-Exploit★ 0V0WKeep3r2022-03-10CandidatePoC-in-GitHub · osungjinwoo/CVE-2022-0847-Dirty-Pipe★ 0osungjinwoo2022-03-10CandidatePoC-in-GitHub · Greetdawn/CVE-2022-0847-DirtyPipe-★ 0Greetdawn2022-03-11CandidatePoC-in-GitHub · crusoe112/DirtyPipePythonA Python-based DirtyPipe (CVE-2022-0847) POC to pop a root shell★ 10crusoe1122022-03-11CandidatePoC-in-GitHub · nanaao/dirtyPipe-automaticRootCVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.★ 4nanaao2022-03-12CandidatePoC-in-GitHub · arttnba3/CVE-2022-0847my personal exploit of CVE-2022-0847(dirty pipe)★ 6arttnba32022-03-12CandidatePoC-in-GitHub · AlexisAhmed/CVE-2022-0847-DirtyPipe-ExploitsA collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.★ 733AlexisAhmed2022-03-12CandidatePoC-in-GitHub · sa-infinity8888/Dirty-Pipe-CVE-2022-0847CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.★ 3sa-infinity88882022-03-13CandidatePoC-in-GitHub · realbatuhan/dirtypipetesterDirty Pipe (CVE-2022-0847) zafiyeti kontrolü★ 1realbatuhan2022-03-13CandidatePoC-in-GitHub · CYB3RK1D/CVE-2022-0847-POCdirtypipe★ 2CYB3RK1D2022-03-14CandidatePoC-in-GitHub · breachnix/dirty-pipe-pocCVE-2022-0847 POC★ 15breachnix2022-03-14CandidatePoC-in-GitHub · Shotokhan/cve_2022_0847_shellcodeImplementation of CVE-2022-0847 as a shellcode★ 3Shotokhan2022-03-14CandidatePoC-in-GitHub · githublihaha/DirtyPIPE-CVE-2022-0847★ 0githublihaha2022-03-15CandidatePoC-in-GitHub · MrP1xel/CVE-2022-0847-dirty-pipe-kernel-checkerPython script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847★ 3MrP1xel2022-03-15CandidatePoC-in-GitHub · jpts/CVE-2022-0847-DirtyPipe-Container-BreakoutPoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847★ 2jpts2022-03-15CandidatePoC-in-GitHub · LudovicPatho/CVE-2022-0847_dirty-pipeHacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)★ 10LudovicPatho2022-03-18CandidatePoC-in-GitHub · DanaEpp/pwncat_dirtypipepwncat module that automatically exploits CVE-2022-0847 (dirtypipe)★ 4DanaEpp2022-03-20CandidatePoC-in-GitHub · tmoneypenny/CVE-2022-0847Dirty Pipe - CVE-2022-0847★ 2tmoneypenny2022-03-22CandidatePoC-in-GitHub · scopion/dirty-pipeExploit for Dirty-Pipe (CVE-2022-0847)★ 1scopion2022-03-31CandidatePoC-in-GitHub · stfnw/Debugging_Dirty_Pipe_CVE-2022-0847Presentation slides and supplementary material★ 0stfnw2022-04-01CandidatePoC-in-GitHub · drapl0n/dirtypipeDirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability is tracked as CVE-2022-0847 and allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root.★ 7drapl0n2022-04-02CandidatePoC-in-GitHub · 0xr1l3s/CVE-2022-0847Linux “Dirty Pipe” vulnerability gives unprivileged users root access★ 00xr1l3s2022-04-03CandidatePoC-in-GitHub · mhanief/dirtypipeDirty Pipe Vulnerability Detection Script - RHSB-2022-002 Dirty Pipe - kernel arbitrary file manipulation - (CVE-2022-0847)★ 2mhanief2022-04-06CandidatePoC-in-GitHub · tufanturhan/CVE-2022-0847-L-nux-PrivEsc★ 0tufanturhan2022-04-15CandidatePoC-in-GitHub · rexpository/linux-privilege-escalationScripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability★ 9rexpository2022-04-17CandidatePoC-in-GitHub · isaiahsimeone/COMP3320-VAPTFiles required to demonstrate CVE-2022-0847 vulnerability in Linux Kernel v5.8★ 0isaiahsimeone2022-05-08CandidatePoC-in-GitHub · VinuKalana/DirtyPipe-CVE-2022-0847This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847★ 2VinuKalana2022-05-17CandidatePoC-in-GitHub · ihenakaarachchi/debian11-dirty_pipe-patcherA Simple bash script that patches the CVE-2022-0847 (dirty pipe) kernel vulnerability on Debian 11★ 2ihenakaarachchi2022-05-21CandidatePoC-in-GitHub · greenhandatsjtu/CVE-2022-0847-Container-EscapeCVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸★ 37greenhandatsjtu2022-06-04CandidatePoC-in-GitHub · jxpsx/CVE-2022-0847-DirtyPipe-ExploitsA collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.★ 0jxpsx2022-06-30CandidatePoC-in-GitHub · airbus-cert/dirtypipe-ebpf_detectionAn eBPF detection program for CVE-2022-0847★ 29airbus-cert2022-07-05CandidatePoC-in-GitHub · rabomen/Dirty-Pipeexp of CVE-2022-0847★ 2rabomen2022-07-05CandidatePoC-in-GitHub · eduquintanilha/CVE-2022-0847-DirtyPipe-ExploitsCOMPILED★ 3eduquintanilha2022-08-01CandidatePoC-in-GitHub · EagleTube/CVE-2022-0847Modified dirtypipe script into auto root without have to search a file manually to hijack suid binary.★ 3EagleTube2022-08-13CandidatePoC-in-GitHub · KianaBin/CVE-2022-0847-Container-EscapeCVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸★ 5KianaBin2022-08-18CandidatePoC-in-GitHub · notl0cal/dpipeProof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)★ 0notl0cal2022-08-31CandidatePoC-in-GitHub · Gustavo-Nogueira/Dirty-Pipe-ExploitsCVE-2022-0847(Dirty Pipe) vulnerability exploits.★ 2Gustavo-Nogueira2022-09-11CandidatePoC-in-GitHub · b4dboy17/Dirty-Pipe-OneshotCompled version of CVE-2022-0847 aka Dirty Pipe. Just one shot to root them all :D★ 1b4dboy172022-10-11CandidatePoC-in-GitHub · edsonjt81/CVE-2022-0847-DirtyPipe-★ 0edsonjt812022-10-12CandidatePoC-in-GitHub · mattlloyddavies/ps-lab-cve-2022-0847Resources required for building Pluralsight CVE-2022-0847 lab★ 1mattlloyddavies2022-11-16CandidatePoC-in-GitHub · qwert419/linux-修改版CVE-2022-0847★ 7qwert4192022-11-21CandidatePoC-in-GitHub · DataFox/CVE-2022-0847CVE-2022-0847★ 0DataFox2022-12-21CandidatePoC-in-GitHub · pmihsan/Dirty-Pipe-CVE-2022-0847Dirty Pipe Kernel Vulnerability Exploit★ 0pmihsan2022-12-30CandidatePoC-in-GitHub · ajith737/Dirty-Pipe-CVE-2022-0847-POCs★ 0ajith7372023-01-04CandidatePoC-in-GitHub · mutur4/CVE-2022-0847Drity Pipe Linux Kernel 1-Day Exploit★ 2mutur42023-01-24CandidatePoC-in-GitHub · orsuprasad/CVE-2022-0847-DirtyPipe-Exploits★ 0orsuprasad2023-02-26CandidatePoC-in-GitHub · JlSakuya/CVE-2022-0847-container-escapeA simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.★ 2JlSakuya2023-04-26CandidatePoC-in-GitHub · jonathanbest7/cve-2022-0847check cve-2022-0847★ 0jonathanbest72023-04-30CandidatePoC-in-GitHub · 0xeremus/dirty-pipe-pocPOC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability★ 20xeremus2023-06-20CandidatePoC-in-GitHub · h4ckm310n/CVE-2022-0847-eBPFAn eBPF program to detect attacks on CVE-2022-0847★ 8h4ckm310n2023-07-06CandidatePoC-in-GitHub · joeymeech/CVE-2022-0847-Exploit-ImplementationUsing CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.★ 1joeymeech2023-07-09CandidatePoC-in-GitHub · pashayogi/DirtyPipeCVE: CVE-2022-0847★ 1pashayogi2023-09-17CandidatePoC-in-GitHub · ayushx007/CVE-2022-0847-dirty-pipe-checkerBash script to check if kernel is vulnerable★ 0ayushx0072023-10-25CandidatePoC-in-GitHub · ayushx007/CVE-2022-0847-DirtyPipe-Exploits★ 0ayushx0072023-11-05CandidatePoC-in-GitHub · solomon12354/LockingGirl-----CVE-2022-0847-Dirty_Pipe_virus★ 0solomon123542023-12-28CandidatePoC-in-GitHub · letsr00t/CVE-2022-0847★ 0letsr00t2024-02-15CandidatePoC-in-GitHub · karanlvm/DirtyPipe-ExploitProof of concept for CVE-2022-0847★ 2karanlvm2024-04-19CandidatePoC-in-GitHub · xsxtw/CVE-2022-0847★ 0xsxtw2024-05-01CandidatePoC-in-GitHub · muhammad1596/CVE-2022-0847-dirty-pipe-checker★ 1muhammad15962024-06-04CandidatePoC-in-GitHub · muhammad1596/CVE-2022-0847-DirtyPipe-Exploits★ 0muhammad15962024-06-06CandidatePoC-in-GitHub · aswanepo/DirtyPipeWorking Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.★ 0aswanepo2024-11-25CandidatePoC-in-GitHub · JustinYe377/CTF-CVE-2022-0847★ 0JustinYe3772025-01-07CandidatePoC-in-GitHub · mithunmadhukuttan/Dirty-Pipe-ExploitThe **Dirty Pipe exploit (CVE-2022-0847)** is a Linux kernel vulnerability (v5.8+) allowing unprivileged attackers to overwrite arbitrary files via a flaw in the pipe mechanism. This leads to privilege escalation, granting root access. Similar to Dirty Cow but easier to exploit. Fix: Update to a patched kernel version.★ 0mithunmadhukuttan2025-01-08CandidatePoC-in-GitHub · Mephierr/DirtyPipe_exploitCVE-2022-0847★ 1Mephierr2025-01-21CandidatePoC-in-GitHub · RogelioPumajulca/CVE-2022-0847★ 0RogelioPumajulca2025-02-09CandidatePoC-in-GitHub · cypherlobo/DirtyPipe-BSIA root exploit for CVE-2022-0847 (Dirty Pipe)★ 0cypherlobo2025-03-25CandidatePoC-in-GitHub · byteReaper77/Dirty-PipeSimple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation by leveraging improper handling of pipe buffers in the kernel.★ 3byteReaper772025-04-19CandidatePoC-in-GitHub · morgenm/dirtypipeDirtyPipe (CVE-2022-0847) exploit written in Rust★ 0morgenm2025-07-01CandidatePoC-in-GitHub · Scouserr/cve-2022-0847-poc-dockerimage★ 0Scouserr2025-08-07CandidatePoC-in-GitHub · Shadow-Spinner/CVE-2022-0847exploit of CVE-2022-0847 which directly remove password of the root account★ 0Shadow-Spinner2025-09-11CandidatePoC-in-GitHub · xiaoLvChen/CVE-2022-0847CVE-2022-0847(Linux 内核本地提权漏洞)★ 1xiaoLvChen2026-01-07CandidatePoC-in-GitHub · stfnw/reproducer-poc-CVE-2022-0847Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.★ 0stfnw2026-01-28CandidatePoC-in-GitHub · bluedragonsecurity/Linux-Kernel-Dirty-Pipe-Exploitation-Logic-Bug-Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)★ 3bluedragonsecurity2026-02-01CandidatePoC-in-GitHub · SimoesCTT/Chrono-Drip-Temporal-Viscosity-Exploitation-Framework-CVE-2022-0847This tool demonstrates the application of fundamental physics discoveries to cybersecurity.★ 0SimoesCTT2026-02-07CandidatePoC-in-GitHub · real-tim-johnston/megaquagga-pentest-reportBlack box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847★ 0real-tim-johnston2026-03-01CandidatePoC-in-GitHub · JeevanAnand1202/Penetration-TestFull penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file upload → reverse shell → kernel privilege escalation (Dirty Pipe, CVE-2022-0847).★ 0JeevanAnand12022026-04-02CandidatePoC-in-GitHub · gaganhm3018-art/CVE-2022-0847-Dirty-Pipe-this is a repo who is facing a escalation issue in their linux system and a news regarding problem of "Dirty pipeline"★ 0gaganhm3018-art2026-05-02CandidatePoC-in-GitHub · t1ckprivate/CVE-2022-0847-Dirty-Pipe★ 0t1ckprivate2026-06-06CandidatePoC-in-GitHub · vudangducminh/CVE-2022-0847★ 0vudangducminh2026-09-10CandidateSploitusAutomatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shelKitPloit2026-09-02T21:29:33Candidatekitploit.comAutomatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shelen2026-09-02T21:29:33Candidate