CVE-2022-2590 is a race condition in the Linux kernel memory subsystem's handling of copy-on-write breakage for private read-only shared memory mappings. A successful race allows an unprivileged local user to obtain write access to mappings intended to be read-only, enabling privilege escalation on the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a local Linux kernel privilege-boundary bypass PoC for CVE-2022-2590, described as a Dirty COW variant restricted to shmem. Structure is small: README.md provides a detailed vulnerability analysis and exploitation race timeline; README_IN_KOREAN.md links to an external blog post; poc.c is the actual proof-of-concept; poc_deayzl.patch is not an exploit payload but a kernel instrumentation patch used to make the race easier to observe and reproduce. The main exploit capability is unauthorized modification of a read-only shared-memory-backed file mapping. The PoC opens a user-supplied target file read-only, mmaps one page as MAP_PRIVATE|PROT_READ, opens /proc/self/mem read-write, and then races three activities: (1) madvise(MADV_DONTNEED) to invalidate the page, (2) a userfaultfd handler thread that services minor shmem faults with UFFDIO_CONTINUE, and (3) a pwrite() to /proc/self/mem at the mapped address. This is intended to satisfy the kernel conditions around FOLL_FORCE, FOLL_COW, and pte_dirty so that follow_page_pte/can_follow_write_pte ultimately permits writing attacker-controlled bytes into a page that should remain read-only. In poc.c, the payload is minimal and hardcoded: the string "AAAA". The exploit is therefore a proof-of-concept rather than a generalized weaponized tool. It demonstrates the vulnerability by printing old file contents, triggering the race, then printing new contents to show the overwrite. There is no remote communication, no persistence, and no post-exploitation logic. The patch file modifies Linux kernel source files (fs/userfaultfd.c, mm/gup.c, mm/memory.c, mm/shmem.c, mm/userfaultfd.c, and Makefile) primarily to add printk tracing and timing assistance around the vulnerable execution path. This indicates the repository’s purpose is educational/research-focused: to explain and reliably reproduce the race rather than provide a stealthy exploit. Overall, this is a genuine local kernel exploit PoC targeting vulnerable Linux kernels with userfaultfd minor shmem support enabled, demonstrating arbitrary write to read-only shmem-backed content via a carefully orchestrated race.
This repository provides a detailed analysis and proof-of-concept (PoC) exploit for CVE-2022-2590, a vulnerability in the Linux kernel (6.0.0-rc1 and possibly other versions) that allows an attacker to write arbitrary data to a read-only shared memory page. The repository contains four files: a comprehensive README.md with technical analysis and exploitation steps, a Korean-language summary, a C-based PoC (poc.c), and a patch file (poc_deayzl.patch) for kernel instrumentation and debugging. The PoC demonstrates a race condition using userfaultfd, madvise, and pwrite to bypass memory protections and overwrite a read-only file in /dev/shm. The patch file adds kernel debug output to help trace the exploit's execution. The exploit requires local access and specific kernel configuration, and it targets the Linux kernel's memory management subsystem. The main fingerprintable endpoints are the shared memory file (/dev/shm/foo) and the process memory interface (/proc/self/mem). The exploit is a proof-of-concept and does not provide a weaponized payload, but it clearly demonstrates the vulnerability and its impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.