CVE-2022-29799 is a Nimbuspwn directory-traversal vulnerability in Linux networkd-dispatcher. Functions do not sanitize paths according to OperationalState or AdministrativeState, allowing traversal outside the /etc/networkd-dispatcher base directory. It is distinct from CVE-2022-29800, which covers the related symlink-race and time-of-check-to-time-of-use race conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a real local privilege escalation PoC for NimbusPwn, targeting CVE-2022-29799 and CVE-2022-29800 in networkd-dispatcher on Linux. The main exploit is nimbuspwn.c, a standalone C program using libdbus-1 to interact with the system D-Bus. Its core capability is to impersonate org.freedesktop.network1 on the system bus, emit a forged PropertiesChanged signal on /org/freedesktop/network1/link/_32, and supply a malicious OperationalState value containing path traversal. That traversal is combined with a symlink TOCTOU race so the root-owned networkd-dispatcher daemon enumerates and executes attacker-controlled scripts. The payload is simple but effective: it writes a shell script that copies the selected shell (default /bin/sh) to /tmp/sh, sets mode 4777, and then the exploit executes /tmp/sh -p to obtain a root shell. The exploit also includes a safer --check mode that only tests the key precondition: whether the attacker can claim the D-Bus name org.freedesktop.network1. If the name is already owned or cannot be claimed, the tool reports the target as likely not vulnerable. This makes the repository more than a pure weaponized dropper; it includes both validation and exploitation logic. Repository structure is small and focused. Besides the exploit source, there is a Docker-based lab environment: docker/Dockerfile builds an Ubuntu 20.04 container, installs dbus and build dependencies, copies in a bundled vulnerable networkd-dispatcher 2.0 Python script, and sets a permissive lab-only D-Bus policy. docker/entrypoint.sh starts a system D-Bus daemon, launches the vulnerable dispatcher as root, compiles nimbuspwn.c, and drops the user into an unprivileged shell as user pwn. docker/fake-networkctl stubs out networkctl output so the vulnerable dispatcher can operate without full systemd-networkd. docker/lab-nimbuspwn.conf is the intentionally insecure D-Bus policy that allows any user to own org.freedesktop.network1, reproducing the exploit precondition. docker-compose.yml provides a simple way to build and run the lab. Overall, this is an operational local exploit PoC with a bundled reproducible lab. It is not a remote exploit and does not target network services directly; the relevant attack surface is local D-Bus message spoofing and filesystem race/path traversal against networkd-dispatcher.
This repository is a real local privilege escalation PoC for NimbusPwn against networkd-dispatcher versions earlier than 2.1 on Linux. The main exploit is a standalone C program, nimbuspwn.c, which uses libdbus to connect to the system bus, claim the well-known name org.freedesktop.network1, and emit a forged PropertiesChanged signal on /org/freedesktop/network1/link/_32. The malicious OperationalState value contains a path traversal sequence that abuses CVE-2022-29799, while the exploit also relies on a symlink race/TOCTOU condition in script directory handling (CVE-2022-29800). Together these flaws cause the root-owned networkd-dispatcher daemon to execute attacker-controlled scripts. The exploit’s core capability is local root escalation. Its payload is simple but effective: it generates a shell script that copies a chosen shell binary (default /bin/sh) to /tmp/sh, sets mode 4777, and then executes that SUID copy with -p to preserve effective UID 0. The exploit includes a non-destructive --check mode that only tests whether the org.freedesktop.network1 bus name is claimable, which it treats as a likely-vulnerable precondition, without planting files or racing. Repository structure is small and focused. The primary code artifact is nimbuspwn.c. Supporting files include documentation (README, SECURITY, CONTRIBUTING), formatting config, and a self-contained Docker lab. The Docker lab contains a Dockerfile, entrypoint script, a fake networkctl helper, a permissive D-Bus policy file, and a vendored vulnerable networkd-dispatcher 2.0 Python script. The lab starts a system D-Bus instance, launches the vulnerable dispatcher as root, compiles the exploit, and drops the user into an unprivileged shell for reproduction. This makes the repository both a PoC and a reproducible test environment. No external C2 or remote network targets are present; the attack vector is strictly local. The most fingerprintable observables are the D-Bus name/interface/object path values, the traversal string pattern ../../../tmp/nimbuspwn_<rand>/poc, the dropped SUID shell path /tmp/sh, and the lab-specific D-Bus policy file /etc/dbus-1/system.d/lab-nimbuspwn.conf. Overall maturity is OPERATIONAL: the exploit is functional, includes a working payload and retry logic for the race, but is still a standalone PoC rather than a modular framework component.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of the Nimbuspwn local privilege-escalation vulnerabilities in networkd-dispatcher on Linux. The issues can enable an adversary with local shell access to escalate privileges and deploy malicious payloads, including ransomware.
A directory traversal vulnerability in networkd-dispatcher, part of the Nimbuspwn vulnerability chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.