CVE-2022-0185
Last modified
CVE-2022-0185 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.. CISA has confirmed active exploitation in the wild. EPSS estimates a 25.15% chance of exploitation in the next 30 days.
Description
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.1, < 5.4.173 |
| Linux | Linux Kernel | >= 5.5, < 5.10.93 |
| Linux | Linux Kernel | >= 5.11, < 5.15.16 |
| Linux | Linux Kernel | >= 5.16, < 5.16.2 |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H300e Firmware | All versions |
| Netapp | H500e Firmware | All versions |
| Netapp | H700e Firmware | All versions |
| Netapp | H410s Firmware | All versions |
References
- https://github.com/Crusaders-of-Rust/CVE-2022-0185Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220225-0003/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/18/7Mailing List, Patch, Third Party Advisory
- https://www.willsroot.io/2022/01/cve-2022-0185.htmlExploit, Third Party Advisory
- https://github.com/Crusaders-of-Rust/CVE-2022-0185Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220225-0003/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/01/18/7Mailing List, Patch, Third Party Advisory
- https://www.willsroot.io/2022/01/cve-2022-0185.htmlExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0185US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-0185?
How severe is CVE-2022-0185?
How do I fix CVE-2022-0185?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-0179snipe-it is vulnerable to Missing Authorization5.4
- CVE-2022-0180Cross-site request forgery (CSRF) vulnerability in Quiz And …8.8
- CVE-2022-0181Reflected cross-site scripting vulnerability in Quiz And Sur…6.1
- CVE-2022-0182Stored cross-site scripting vulnerability in Quiz And Survey…5.4
- CVE-2022-0183Missing encryption of sensitive data vulnerability in 'MIRUP…4.6
- CVE-2022-0184Insufficiently protected credentials vulnerability in 'TEPRA…4.3
- CVE-2022-0186The Image Photo Gallery Final Tiles Grid WordPress plugin be…5.4
- CVE-2022-0188The CMP WordPress plugin before 4.0.19 allows any user, even…5.3
- CVE-2022-0189The WP RSS Aggregator WordPress plugin before 4.20 does not …6.1
- CVE-2022-0190The Ad Invalid Click Protector (AICP) WordPress plugin befor…8.8
- CVE-2022-0191The Ad Invalid Click Protector (AICP) WordPress plugin befor…6.5
- CVE-2022-0192A DLL search path vulnerability was reported in Lenovo PCMan…7.8
Are you affected by CVE-2022-0185?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
