CyberSec.Space Logo
CVEブラウザに戻る

CVE-2022-0185

🔥 Known Exploited (CISA KEV)HIGH
8.4
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-02-11
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Affected Platforms (CPE)

💻
Linux

Linux Kernel

>= 5.1 and < 5.4.173>= 5.5 and < 5.10.93>= 5.11 and < 5.15.16>= 5.16 and < 5.16.2
💻
Netapp

H410c Firmware

All versions
💻
Netapp

H300s Firmware

All versions
💻
Netapp

H500s Firmware

All versions

References & Advisories

関連する脆弱性情報