Vulnerability Intelligence Report
Linux Kernel Heap-Based Buffer Overflow Vulnerability
CVE-2022-0185
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.4
HIGH
Exploitability:2.6
Impact Score:5.9
EPSS Probability:25.15%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-190 ↗Integer Overflow or Wraparound CWE-190
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| netapp | h410c_firmware | all |
| netapp | h410c | all |
| netapp | h300s_firmware | all |
| netapp | h300s | all |
| netapp | h500s_firmware | all |
| netapp | h500s | all |
| netapp | h700s_firmware | all |
| netapp | h700s | all |
| netapp | h300e_firmware | all |
| netapp | h300e | all |
| netapp | h500e_firmware | all |
| netapp | h500e | all |
| netapp | h700e_firmware | all |
| netapp | h700e | all |
| netapp | h410s_firmware | all |
| netapp | h410s | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
EPSS Score
25.151%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2022-01-11T00:00:00 |
| Published | 2022-02-11T17:40:57 |
| Last Updated | 2025-10-21T23:15:46 |
Community Chatter & Buzz