CVE-2022-0185

HIGH KEV

Linux kernel - Privilege Escalation

Title source: llm

Description

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Exploits (11)

nomisec WORKING POC 378 stars
by Crusaders-of-Rust · local
https://github.com/Crusaders-of-Rust/CVE-2022-0185
nomisec WORKING POC 38 stars
by chenaotian · local
https://github.com/chenaotian/CVE-2022-0185
nomisec WORKING POC 17 stars
by veritas501 · local
https://github.com/veritas501/CVE-2022-0185-PipeVersion
nomisec WORKING POC 5 stars
by discordianfish · poc
https://github.com/discordianfish/cve-2022-0185-crash-poc
nomisec WORKING POC 3 stars
by featherL · local
https://github.com/featherL/CVE-2022-0185-exploit
nomisec WORKING POC 2 stars
by dcheng69 · poc
https://github.com/dcheng69/CVE-2022-0185-Case-Study
gitlab WORKING POC
by Skwgasnaw · local
https://gitlab.com/Skwgasnaw/CVE-2022-0185
nomisec WORKING POC
by prabeershakya · poc
https://github.com/prabeershakya/CVE-2022-0185-POC
nomisec WORKING POC
by shakyanayann · poc
https://github.com/shakyanayann/CVE-2022-0185
nomisec WORKING POC
by sandesh9978 · poc
https://github.com/sandesh9978/CVE-2022-0185-Analysis-and-Exploit
nomisec WORKING POC
by khaclep007 · poc
https://github.com/khaclep007/CVE-2022-0185

Scores

CVSS v3 8.4
EPSS 0.0157
EPSS Percentile 81.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2024-08-21
VulnCheck KEV 2024-03-21
InTheWild.io 2024-08-21
ENISA EUVD EUVD-2022-15389

Classification

CWE
CWE-190 CWE-191
Status published

Affected Products (9)

linux/linux_kernel < 5.4.173
netapp/h410c_firmware
netapp/h300s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/h300e_firmware
netapp/h500e_firmware
netapp/h700e_firmware
netapp/h410s_firmware

Timeline

Published Feb 11, 2022
KEV Added Aug 21, 2024
Tracked Since Feb 18, 2026