logo

Dirty Pipe Linux Vulnerability: Overwriting Files in Container Images

ID: 79dc6e23-c4e4-5cdd-a9b8-a7ca3342d411

STIX ID: report--79dc6e23-c4e4-5cdd-a9b8-a7ca3342d411

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2022-03-08

Date Updated: 2026-04-26

...
...

This report details CVE-2022-0847 (“Dirty Pipe”), a Linux kernel vulnerability (affecting kernel 5.8+) that permits local attackers — including processes running inside containers — to overwrite files from read-only image layers or read-only host mounts; the author demonstrates a working exploit against an ubuntu:21.04 Docker image, explains risks to shared container images and mounted volumes, and recommends immediate kernel patching and host reboots as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.