CVE-2022-0185: Linux Kernel Heap-Based Buffer Overflow Vulnerability

High severity, CVSS 8.4. Actively exploited: in CISA KEV since 2024-08-21. EPSS: 25.2% chance of exploitation in the next 30 days.

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Affected products

  • Linux Linux Kernel: from 5.1, before 5.4.173 (fixed in 5.4.173); from 5.5, before 5.10.93 (fixed in 5.10.93); from 5.11, before 5.15.16 (fixed in 5.15.16); from 5.16, before 5.16.2 (fixed in 5.16.2)
  • Netapp h300e Firmware: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500e Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700e Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified

Published 2022-02-11. Last modified 2026-06-17.