CVSS v3.1 Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 76.8% of known CVEs.
Aug 21, 2024
Sep 11, 2024
Threat Analysis
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.
Remediation Directive
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
External Intelligence
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=722d94847de2
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2022-0185