peter bassill · operator
$ cve CVE-2022-0185 JSON

CVE-2022-0185 KEV

8.4
HIGH · CVSS 3.1 · EPSS 25.2% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2024-09-11.

Description

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Scoring

CVSS8.4 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS25.15% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-190
On CISA KEVyes — remediate by 2024-09-11
Public exploitnone known
Published2022-02-11
Last modified2026-06-17

CISA KEV

NameLinux Kernel Heap-Based Buffer Overflow Vulnerability
Added2024-08-21
Due2024-09-11
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (17)

VendorProduct
linuxlinux kernel
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware

References

→ the Explorer  ·  watch your stack  ·  NVD