8.4

CVE-2022-0185

Warnung
Exploit
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.1 < 5.4.173
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.93
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.16
Linux ≫ Linux Kernel Version >= 5.16 < 5.16.2
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

21.08.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Heap-Based Buffer Overflow Vulnerability

Schwachstelle

Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.

Beschreibung

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 25.15% 0.977
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

CWE-191 Integer Underflow (Wrap or Wraparound)

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de2
Patch
Mailing List
https://github.com/Crusaders-of-Rust/CVE-2022-0185
Third Party Advisory
Exploit
https://security.netapp.com/advisory/ntap-20220225-0003/
Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/01/18/7
Patch
Third Party Advisory
Mailing List
https://www.willsroot.io/2022/01/cve-2022-0185.html
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0185
US Government Resource