A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-0185.json"
[
{
"events": [
{
"introduced": "5.1"
},
{
"fixed": "5.4.173"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.93"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.15.16"
}
]
},
{
"events": [
{
"introduced": "5.16"
},
{
"fixed": "5.16.2"
}
]
}
]