Vulnerability record · CVE-2022-0185 · published 11 February 2022
CVE-2022-0185: Linux Kernel Filesystem Context Heap Buffer Overflow
Linux · Linux Kernel
The legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a heap-based buffer overflow. This allows a local user to corrupt kernel memory and escalate privileges on affected systems.
Description
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in the Linux kernel, allows local privilege escalation, has public exploits, and is listed in CISA KEV, indicating active exploitation.
What it is
The legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a heap-based buffer overflow. This allows a local user to corrupt kernel memory and escalate privileges on affected systems.
Impact
An attacker can gain elevated privileges on the system, potentially achieving root access. This can lead to full system compromise, including data theft, persistence, and lateral movement.
Attack surface
The flaw is reachable locally by an unprivileged user if unprivileged user namespaces are enabled; otherwise, it requires namespaced CAP_SYS_ADMIN privilege. No user interaction is needed, and the attack vector is local (AV:L).
Exploitation
CVE-2022-0185 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Public exploit code is available, and EPSS indicates a high probability of exploitation (97.8th percentile).
What to do
- Apply the kernel patch from the official Linux kernel repository or your distribution's updated kernel package immediately.
- If patching is not possible, disable unprivileged user namespaces (e.g., set kernel.unprivileged_userns_clone=0) to reduce the attack surface.
- Restrict local access to systems and enforce least privilege to limit the impact of a successful exploit.
- Monitor vendor advisories (e.g., NetApp) for updates to affected products and apply them as they become available.
- Consider using security modules (e.g., SELinux, AppArmor) to constrain the impact of privilege escalation attempts.
Detection
- Monitor for local privilege escalation attempts by auditing process creation events for unusual parent-child relationships (e.g., unprivileged process spawning a root shell).
- Use kernel auditing (e.g., auditd) to track calls to fsconfig or mount-related syscalls that may trigger the vulnerable legacy_parse_param path.
- Deploy endpoint detection and response (EDR) rules to detect known exploit patterns, such as heap spraying or memory corruption indicators.
- Check for indicators of compromise from public exploits, such as specific file creations or network connections following privilege escalation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-0185 to the Known Exploited Vulnerabilities catalog on 21 August 2024 as "Linux Kernel Heap-Based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 11 September 2024.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de2 | Mailing ListPatch |
| https://github.com/Crusaders-of-Rust/CVE-2022-0185 | ExploitThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20220225-0003/ | Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2022/01/18/7 | Mailing ListPatchThird Party Advisory |
| https://www.willsroot.io/2022/01/cve-2022-0185.html | ExploitThird Party Advisory |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de2 | Mailing ListPatch |
| https://github.com/Crusaders-of-Rust/CVE-2022-0185 | ExploitThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20220225-0003/ | Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2022/01/18/7 | Mailing ListPatchThird Party Advisory |
| https://www.willsroot.io/2022/01/cve-2022-0185.html | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0185 | US Government Resource |
Track CVE-2022-0185 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0185), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.