# Replit — Escaping Dirty Pipe (a.k.a. CVE-2022-0847), mostly unscathed

- Company: Replit (replit.com)
- Announced: 2022-03-16T18:00:00+00:00
- Category: not stated
- Coverage: not counted
- Announcement: no
- Group: routine
- Source: https://replit.com/blog/dirtypipe-kernel-vulnerability
- Record: https://forck.live/items/18154-escaping-dirty-pipe-a-k-a-cve-2022-0847-mostly-unscathed
- Subject: Replit Agent

Replit explains how the Dirty Pipe kernel vulnerability (CVE-2022-0847) impacted its platform. The company found that its existing no-new-privs bit and limited container capabilities prevented privilege escalation, but the page cache sharing across containers meant a malicious user could still modify shared binaries like /bin/sh. Replit patched the kernel as soon as a fix was available and reports no known successful exploitation.

## Evidence

Verbatim from https://replit.com/blog/dirtypipe-kernel-vulnerability:

> We very recently enabled the no new privs bit that negated the effects of the setuid bit, so the user was greeted with a normal shell instead of a root shell. This meant that the scariest part of this exploit (escalation of privileges) was not possible in our system.

---

Record: https://forck.live/items/18154-escaping-dirty-pipe-a-k-a-cve-2022-0847-mostly-unscathed
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
