A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
History

Thu, 22 Aug 2024 06:15:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2022-02-11T17:40:57

Updated: 2024-08-22T12:49:16.141Z

Reserved: 2022-01-11T00:00:00

Link: CVE-2022-0185

cve-icon Vulnrichment

Updated: 2024-08-02T23:18:42.536Z

cve-icon NVD

Status : Analyzed

Published: 2022-02-11T18:15:10.890

Modified: 2024-09-04T01:00:01.057

Link: CVE-2022-0185

cve-icon Redhat

Severity : Important

Publid Date: 2022-01-18T18:41:00Z

Links: CVE-2022-0185 - Bugzilla