PT-2022-1934 · Linux+10 · Linux Kernel+10

Chop0

+6

·

Published

2022-01-18

·

Updated

2026-04-08

·

CVE-2022-0185

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions 5.1 through 5.15.1 Linux Kernel versions prior to 5.16.2 Linux Kernel versions prior to 5.15.16 Linux Kernel versions prior to 5.10.93 Linux Kernel versions prior to 5.4.173
Description A heap-based buffer overflow flaw was found in the way the legacy parse param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged local user able to open a filesystem that does not support the Filesystem Context API could use this flaw to escalate their privileges on the system. The vulnerability allows a local attacker to cause a denial of service or execute arbitrary code. It can also be used to escape Kubernetes containers.
Recommendations For Linux Kernel versions 5.1 through 5.15.1, update to version 5.16.2 or later. For Linux Kernel versions prior to 5.15.16, update to version 5.15.16 or later. For Linux Kernel versions prior to 5.10.93, update to version 5.10.93 or later. For Linux Kernel versions prior to 5.4.173, update to version 5.4.173 or later. As a temporary workaround, consider setting the sysctl "user.max user namespaces" to 0 to prevent exploitation.

Exploit

Fix

Integer Underflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0188
ALSA-2022_0188
ALSA-2024_2394
ALSA-2025_16880
ALT-PU-2022-1104
ALT-PU-2022-1105
ALT-PU-2022-1108
ALT-PU-2022-1135
ALT-PU-2022-1137
ALT-PU-2022-1138
ALT-PU-2022-1192
ALT-PU-2022-1267
ALT-PU-2022-1289
ALT-PU-2022-1298
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2022-1428
ALT-PU-2022-1441
ALT-PU-2022-1467
ALT-PU-2022-1540
ALT-PU-2023-4894
AZL-8578
BDU:2022-01472
CESA-2022_0176
CESA-2022_0188
CESA-2022_0232
CVE-2022-0185
DSA-5050-1
ELSA-2022-0188
ELSA-2022-9028
ELSA-2022-9029
ELSA-2022-9147
ELSA-2022-9148
LSN-0084-1
MGASA-2022-0026
MGASA-2022-0027
OPENSUSE-SU-2022:0169-1
OPENSUSE-SU-2022:0198-1
OPENSUSE-SU-2022_0169-1
OPENSUSE-SU-2022_0198-1
OPENSUSE-SU-2024:11775-1
OPENSUSE-SU-2024:13704-1
RHSA-2022:0176
RHSA-2022:0186
RHSA-2022:0187
RHSA-2022:0188
RHSA-2022:0231
RHSA-2022:0232
RHSA-2022:0540
RHSA-2022_0176
RHSA-2022_0188
RLSA-2022:0176
RLSA-2022:0188
RLSA-2022_0176
RLSA-2022_0188
SUSE-SU-2022:0169-1
SUSE-SU-2022:0197-1
SUSE-SU-2022:0198-1
SUSE-SU-2022:0238-1
SUSE-SU-2022:0239-1
SUSE-SU-2022:0241-1
SUSE-SU-2022:0254-1
SUSE-SU-2022:0257-1
SUSE-SU-2022:0262-1
SUSE-SU-2022:0270-1
SUSE-SU-2022:0288-1
SUSE-SU-2022:0289-1
SUSE-SU-2022:0291-1
SUSE-SU-2022:0292-1
SUSE-SU-2022:0293-1
SUSE-SU-2022:0295-1
SUSE-SU-2022_0169-1
SUSE-SU-2022_0197-1
SUSE-SU-2022_0198-1
SUSE-SU-2022_0238-1
SUSE-SU-2022_0239-1
SUSE-SU-2022_0241-1
SUSE-SU-2022_0254-1
SUSE-SU-2022_0257-1
SUSE-SU-2022_0262-1
SUSE-SU-2022_0270-1
SUSE-SU-2022_0288-1
SUSE-SU-2022_0289-1
SUSE-SU-2022_0291-1
SUSE-SU-2022_0292-1
SUSE-SU-2022_0293-1
SUSE-SU-2022_0295-1
USN-5240-1
USN-5362-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu