GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel (pipe): Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, incl

CVE-2022-0847Kernel, userspace & hypervisorKnown exploitedcurated

Impact

Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, incl. host binaries from inside a container [KEV]

Who can reach it

Any tenant process in a container

What to do

Livepatchable (all major vendors shipped livepatches); otherwise drain + reboot. Highest-priority historical container-escape primitive

Fleet impact

How widespread

Universal - every kernel 5.8+ before 5.16.11/5.15.25/5.10.102, which was the mainstream range on GPU hosts at the time

Cost to remediate

node-reboot - a kernel fix means a reboot of every GPU host unless the operator runs livepatch/kpatch; either way jobs must be drained first

Why it hits the whole fleet

An unprivileged process in a container overwrites read-only files, and the modification lands on the *host* file (page cache is shared), so a tenant overwrites host SUID binaries and takes the node

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.