CVE-2022-0185
Linux Kernel Heap-Based Buffer Overflow Vulnerability
- Published
- Feb 11, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- redhat
- Evidence observed
- Aug 21, 2024
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 97.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
Sources
11CVE-2022-0185 POC and Docker and Analysis write up
- CVE-2022-0185Exploit
CVE-2022-0185
- CVE-2022-0185-Case-StudyExploit
Educational case study and exploit development walkthrough for CVE-2022-0185, a Linux kernel heap-based buffer overflow enabling local privilege escalation. Includes POC, QEMU debugging, and Ubuntu exploit with detailed technical analysis.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.