CVE-2022-0185

CVE Published 2022-02-11
Related CWE(s) CWE-190: Integer Overflow or Wraparound, CWE-191: Integer Underflow (Wrap or Wraparound)
Related Vendor(s) linux, netapp
Related Product(s) h410s_firmware, h300e_firmware, h410c_firmware, h700e_firmware, h700s_firmware, h300s_firmware, h500e_firmware, h500s_firmware, linux_kernel
Exploitation Reported (CISA KEV) 2024-08-21
CVSS 3 Base Score 8.4 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References