← Back to browse · API

CVE-2022-0185

Severity
HIGH
CVSS
8.4
EPSS
0.25151
Risk score
67.4
CISA KEV
Yes
PoC
No
Published
2022-02-11
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-15389
Products
Linux:Kernel, Linux:Kernel 8.4
Sources
cisa.gov CVE-2022-0185
euvd EUVD-2022-15389

Description

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

References