LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-0185: Linux Kernel Heap-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 21, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 11, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-0185 to its Known Exploited Vulnerabilities catalog on Aug 21, 2024, with a federal patch deadline of Sep 11, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not…

CVE-2022-0185 is a heap-based buffer overflow vulnerability in the Linux kernel. It resides in the legacy_parse_param function within the Filesystem Context functionality. An attacker able to open a filesystem that does not support the Filesystem Context API can trigger the flaw and escalate privileges on the affected system.

Privilege escalation in the kernel is serious because it can turn limited local access into full system control. Defenders should treat this as a high-priority issue for any Linux environment where untrusted users or processes can interact with filesystem interfaces, and should confirm all version and configuration details against the vendor advisory.

How it works

The weakness is tracked as CWE-190 (Integer Overflow or Wraparound). In this instance it produces a heap-based buffer overflow inside the Linux kernel’s Filesystem Context code path, specifically the legacy_parse_param function.

Public description indicates that an attacker abuses the condition by opening a filesystem that does not support the Filesystem Context API. The resulting overflow can be leveraged to escalate privileges. Exact trigger conditions, required privileges, and memory-corruption details are not fully enumerated in the available summary; teams must consult the vendor advisory for precise mechanics and any proof-of-concept constraints. No exploit code or step-by-step abuse path is provided here.

Am I affected? How to find it in your systems

The Linux kernel is present on servers, workstations, virtual machines, containers, cloud instances, and many embedded or appliance platforms. Any host running a vulnerable kernel build is potentially in scope.

How to remediate

Apply the vendor-supplied updates that address CVE-2022-0185, or discontinue use of the product if updates are unavailable, as required by CISA guidance.

If you can't patch immediately

Until the update can be applied, reduce the attack surface and increase detection.

If your data may have been exposed

Actively exploited kernel vulnerabilities can lead to full system compromise and subsequent data exposure. If you have reason to believe an attacker gained elevated privileges, treat the host as potentially breached, isolate it, preserve forensic evidence, and follow your incident-response process. Separately, individuals can run a free exposure scan of their email address to check whether that address appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLinux · Kernel
WeaknessCWE-190
Added to CISA KEVAug 21, 2024
Federal patch deadlineSep 11, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities