Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0185

77
FAUCET Score

CVE-2022-0185 is a critical heap-based buffer overflow in the Linux kernel's legacy_parse_param function, affecting Linux and NetApp products. This flaw allows an unprivileged local user to escalate privileges, potentially leading to full system compromise. With a CVSS score of 8.4 (HIGH), it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited (KEV listed) and has garnered significant community discussion and media coverage, despite no public exploit code being available on platforms like Metasploit or ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.1, < 5.4.173CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.93CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 5.16.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.4HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
25.15%
Probability of exploitation in next 30 days
EPSS Percentile
97.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Aug 21, 2024
This CVE's current EPSS score of 0.2515 is in the 99th percentile among its peer group of 3,235 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

boschpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 18781-16823Fixed in: 5.15.26.1-1
microsoftpatch availablevia msrc
Product: 18790-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 kernel 5.10.93.1-4 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.26.1-1 on CBL Mariner 2.0Fixed in: 5.15.26.1-1
mongodbpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-0:4.18.0-305.34.2.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.10-202202081536_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-348.12.2.rt7.143.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-348.12.2.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-rt-0:4.18.0-305.34.2.rt7.107.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch

Vendor Advisories (5)

linuxCVE-2022-0185HIGH

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Feb 11, 2022
microsoft2022-Feb/CVE-2022-0185Important

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

Feb 8, 2022
boschllm-bosch-9c2515a53d286b3cHIGH

Multiple Linux kernel vulnerabilities (CVE-2021-4154, CVE-2021-22600, CVE-2022-0185)

Feb 4, 2022
mongodbllm-mongodb-f0d9b58df6219bd3HIGH

Multiple Linux kernel vulnerabilities (CVE-2021-4154, CVE-2021-22600, CVE-2022-0185)

Feb 2, 2022
redhatCVE-2022-0185Important

kernel: fs_context: heap overflow in legacy parameter handling

Jan 18, 2022

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / Crusaders-of-Rust/CVE-2022-0185
ExploitThird Party Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatch
security.netapp.com / advisory/ntap-20220225-0003
Third Party Advisory
openwall.com / lists/oss-security/2022/01/18/7
Mailing ListPatchThird Party Advisory
willsroot.io / 2022/01/cve-2022-0185.html
ExploitThird Party Advisory