EXPOSURES › CVE-2022-0185
CVE-2022-0185
HIGH ⌖ ON CISA KEV · EXPLOITEDLinux kernel heap-based buffer overflow in legacy_parse_param allows privilege escalation via unsupported filesystems.
This unpatched kernel vulnerability enables privilege escalation when an attacker accesses unsupported filesystems, posing a critical risk to DIB systems relying on Linux infrastructure. The CVE is actively exploited in the wild and linked to ransomware campaigns, making it a high-priority remediation for compliance and operational security.
Shame score — Active exploitation in the wild with ransomware linkage and privilege escalation potential creates significant reputational and compliance risk for vendors shipping unpatched Linux kernels.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.