← Vulnerability feed

Vulnerability record · CVE-2022-0185 · published 11 February 2022

CVE-2022-0185: Linux Kernel Filesystem Context Heap Buffer Overflow

Linux · Linux Kernel

The legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a heap-based buffer overflow. This allows a local user to corrupt kernel memory and escalate privileges on affected systems.

8.4 CVSS 3.1 High CISA KEV since 21 Aug 2024 EPSS 25% · top 2.1% CWE-190 · Integer overflowCWE-191 · CWE-191
8.4CVSS 3.1 base score, v2 7.2
25%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
9Affected product versions listed by NVD
11References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe vulnerability is in the Linux kernel, allows local privilege escalation, has public exploits, and is listed in CISA KEV, indicating active exploitation.

What it is

The legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a heap-based buffer overflow. This allows a local user to corrupt kernel memory and escalate privileges on affected systems.

Impact

An attacker can gain elevated privileges on the system, potentially achieving root access. This can lead to full system compromise, including data theft, persistence, and lateral movement.

Attack surface

The flaw is reachable locally by an unprivileged user if unprivileged user namespaces are enabled; otherwise, it requires namespaced CAP_SYS_ADMIN privilege. No user interaction is needed, and the attack vector is local (AV:L).

Exploitation

CVE-2022-0185 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Public exploit code is available, and EPSS indicates a high probability of exploitation (97.8th percentile).

What to do

  • Apply the kernel patch from the official Linux kernel repository or your distribution's updated kernel package immediately.
  • If patching is not possible, disable unprivileged user namespaces (e.g., set kernel.unprivileged_userns_clone=0) to reduce the attack surface.
  • Restrict local access to systems and enforce least privilege to limit the impact of a successful exploit.
  • Monitor vendor advisories (e.g., NetApp) for updates to affected products and apply them as they become available.
  • Consider using security modules (e.g., SELinux, AppArmor) to constrain the impact of privilege escalation attempts.

Detection

  • Monitor for local privilege escalation attempts by auditing process creation events for unusual parent-child relationships (e.g., unprivileged process spawning a root shell).
  • Use kernel auditing (e.g., auditd) to track calls to fsconfig or mount-related syscalls that may trigger the vulnerable legacy_parse_param path.
  • Deploy endpoint detection and response (EDR) rules to detect known exploit patterns, such as heap spraying or memory corruption indicators.
  • Check for indicators of compromise from public exploits, such as specific file creations or network connections following privilege escalation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-0185 to the Known Exploited Vulnerabilities catalog on 21 August 2024 as "Linux Kernel Heap-Based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 11 September 2024.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0185 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-54085AMI MegaRAC SPx BMC authentication bypass via Redfish Host InterfaceAMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authenti…KEVEPSS 61%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2023-3079Google Chrome V8 type confusion enables heap corruptionCVE-2023-3079 is a type confusion flaw in the V8 JavaScript engine in Google Chrome before 114.0.5735.110. A crafted HTML page can trigger the confus…KEVEPSS 32%analysed8.8CVE-2013-6282Linux kernel ARM get_user/put_user missing address validationThe get_user and put_user API functions in the Linux kernel before 3.5.5 on v6k and v7 ARM platforms fail to validate certain addresses, allowing cra…KEVEPSS 40%analysed8.4CVE-2013-2094Linux Kernel perf_swevent_init Integer Type Flaw Enables Local Privilege EscalationThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, allowing a local user to…KEVEPSS 48%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed

Source: NIST National Vulnerability Database (record CVE-2022-0185), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.