A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
CVE-2022-0185
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2024-08-21), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.4 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 8.4
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS
- 97.7%
- KEV
- ⚠ Exploited
Published
February 11, 2022
Last Modified
November 6, 2025
Advisory Details (5)
Auto-updated Jun 2, 2026Will's Root: CVE-2022-0185 - Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google's KCTF Containers
https://www.willsroot.io/2022/01/cve-2022-0185.htmloss-security - Linux kernel: Heap buffer overflow in fs_context.c since version 5.1
https://www.openwall.com/lists/oss-security/2022/01/18/7GitHub - Crusaders-of-Rust/CVE-2022-0185: CVE-2022-0185 · GitHub
https://github.com/Crusaders-of-Rust/CVE-2022-0185vfs: fs_context: fix up param length parsing in legacy_parse_param - kernel/git/torvalds/linux.git - Linux kernel source tree
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de2Vendor Advisories for CVE-2022-0185(4)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2022:0188Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security and bug fix update
- RHSA-2022:0186Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
- RHSA-2022:0187Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel-rt security and bug fix update
- RHSA-2022:0176Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel-rt security and bug fix update
Patch Availability(9)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | linux-buildinfo-5.11.0-1027-oracle (5.11.0-1027.30) @ hirsute | 2026-07-21 | ubuntu |
| ubuntu | linux-image-unsigned-5.13.0-1010-intel (5.13.0-1010.10) @ focal | 2026-07-21 | ubuntu |
| ubuntu | ibm (5.4.0-1009) @ focal | 2026-07-21 | ubuntu |
| redhat | redhat-virtualization-host-0:4.4.10-202202081536_8.5 | 2022-02-15 | redhat |
| redhat | kpatch-patch | 2022-01-24 | redhat |
| redhat | kernel-rt-0:4.18.0-348.12.2.rt7.143.el8_5 | 2022-01-19 | redhat |
| redhat | kernel-0:4.18.0-348.12.2.el8_5 | 2022-01-19 | redhat |
| redhat | kernel-0:4.18.0-305.34.2.el8_4 | 2022-01-19 | redhat |
| redhat | kernel-rt-0:4.18.0-305.34.2.rt7.107.el8_4 | 2022-01-19 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(7)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Microsoft MSRCCVE-2022-01852022-02-23
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
- Red HatRHSA-2022:0231IMPORTANT2022-01-18
RHSA-2022:0231 — Important
- Red HatRHSA-2022:0232IMPORTANT2022-01-18
RHSA-2022:0232 — Important
- Red HatRHSA-2022:0540IMPORTANT2022-01-18
RHSA-2022:0540 — Important
- UbuntuLSN-0084-1HIGH
Kernel Live Patch Security Notice
- UbuntuUSN-5240-1HIGH
Linux kernel vulnerability
- UbuntuUSN-5362-1HIGH
Linux kernel (Intel IOTG) vulnerabilities
Data Freshness Timeline
(refreshed 61× in last 7d / 235× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 427 total refreshes for this CVE.
- 2026-07-23 02:06 UTCEG score recompute
- 2026-07-22 22:24 UTCEG score recompute
- 2026-07-22 22:24 UTCVendor advisory
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 18:09 UTCEG score recompute
- 2026-07-22 18:09 UTCVendor advisory
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-22 13:53 UTCVendor advisory
- 2026-07-22 09:39 UTCVendor advisory
- 2026-07-22 05:24 UTCVendor advisory
- 2026-07-22 01:10 UTCVendor advisory
- 2026-07-21 20:56 UTCVendor advisory
- 2026-07-21 16:40 UTCEG score recompute
- 2026-07-21 16:40 UTCVendor advisory
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 12:27 UTCVendor advisory
- 2026-07-21 08:12 UTCVendor advisory
- 2026-07-21 03:58 UTCVendor advisory
- 2026-07-20 23:43 UTCVendor advisory
- 2026-07-20 19:29 UTCEG score recompute
- 2026-07-20 19:29 UTCVendor advisory
- 2026-07-20 17:05 UTCEPSS rescore
- 2026-07-20 15:15 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-20 10:59 UTCVendor advisory
- 2026-07-20 06:46 UTCVendor advisory
- 2026-07-20 02:21 UTCVendor advisory
- 2026-07-19 22:06 UTCVendor advisory
- 2026-07-19 17:52 UTCEG score recompute
- 2026-07-19 17:52 UTCVendor advisory
- 2026-07-19 14:29 UTCEPSS rescore
- 2026-07-19 13:37 UTCVendor advisory
- 2026-07-19 09:23 UTCVendor advisory
- 2026-07-19 05:09 UTCEG score recompute
- 2026-07-19 05:09 UTCVendor advisory
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-19 00:55 UTCVendor advisory
- 2026-07-18 20:41 UTCVendor advisory
- 2026-07-18 16:27 UTCVendor advisory
- 2026-07-18 12:12 UTCEG score recompute
- 2026-07-18 12:12 UTCVendor advisory
- 2026-07-18 10:02 UTCEPSS rescore
- 2026-07-18 07:58 UTCVendor advisory
- 2026-07-18 03:44 UTCVendor advisory
- 2026-07-17 23:30 UTCVendor advisory
- 2026-07-17 19:16 UTCVendor advisory
- 2026-07-17 15:02 UTCVendor advisory
- 2026-07-17 10:48 UTCEG score recompute
- 2026-07-17 10:48 UTCVendor advisory
- 2026-07-17 06:34 UTCVendor advisory
- 2026-07-17 02:20 UTCVendor advisory
- 2026-07-16 22:05 UTCVendor advisory
- 2026-07-16 17:51 UTCVendor advisory
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 13:36 UTCVendor advisory
- 2026-07-16 09:22 UTCVendor advisory
- 2026-07-16 05:08 UTCVendor advisory
- 2026-07-16 00:54 UTCVendor advisory
- 2026-07-15 20:40 UTCVendor advisory
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 16:25 UTCVendor advisory
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 12:11 UTCVendor advisory
- 2026-07-15 07:56 UTCVendor advisory
- 2026-07-15 03:43 UTCVendor advisory
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-07-14 23:28 UTCVendor advisory
- 2026-07-14 19:13 UTCVendor advisory
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 14:59 UTCVendor advisory
- 2026-07-14 10:45 UTCVendor advisory
- 2026-07-14 06:31 UTCVendor advisory
- 2026-07-14 02:16 UTCVendor advisory
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 22:02 UTCVendor advisory
- 2026-07-13 17:48 UTCVendor advisory
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 13:34 UTCVendor advisory
- 2026-07-13 09:20 UTCVendor advisory
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-13 05:06 UTCVendor advisory
- 2026-07-13 00:51 UTCVendor advisory
- 2026-07-12 20:37 UTCVendor advisory
- 2026-07-12 16:22 UTCVendor advisory
- 2026-07-12 12:07 UTCVendor advisory
- 2026-07-12 07:53 UTCVendor advisory
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-12 03:39 UTCVendor advisory
- 2026-07-11 23:25 UTCVendor advisory
- 2026-07-11 19:11 UTCVendor advisory
- 2026-07-11 14:57 UTCVendor advisory
- 2026-07-11 10:43 UTCVendor advisory
- 2026-07-11 08:25 UTCEPSS rescore
Publicly available exploits
(6 references)Working exploit code is in the public domain (6 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Open source ↗GitHub PoCdcheng69/CVE-2022-0185-Case-StudyFirst seen Apr 15, 2024
- GitHub PoCfeatherL/CVE-2022-0185-exploitFirst seen Apr 14, 2022
CVE-2022-0185 exploit
Open source ↗ - GitHub PoCveritas501/CVE-2022-0185-PipeVersionFirst seen Apr 5, 2022
CVE-2022-0185 exploit rewritten with pipe primitive
Open source ↗ - GitHub PoCchenaotian/CVE-2022-0185First seen Feb 18, 2022
CVE-2022-0185 POC and Docker and Analysis write up
Open source ↗ - Open source ↗GitHub PoCdiscordianfish/cve-2022-0185-crash-pocFirst seen Jan 26, 2022
- GitHub PoCCrusaders-of-Rust/CVE-2022-0185First seen Jan 19, 2022
CVE-2022-0185
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownmsrc · redhat
Same CWE
10 shownCWE-190 · CWE-191
- CVE-2009-0947EG 9.8CRITICAL
- CVE-2005-0199EG 9.8EPSS 97%CRITICAL
- CVE-2005-1141EG 9.8CRITICAL
- CVE-2005-0102EG 9.8CRITICAL
- CVE-2002-0391EG 9.8EPSS 99%CRITICAL
- CVE-2002-0639EG 9.8EPSS 97%CRITICAL
- CVE-2012-5054NVD 8.8EG 9.0 KEVEPSS 97%HIGH
- CVE-2011-1823NVD 7.8EG 9.0 KEVEPSS 99%HIGH
- CVE-2011-3631EG 8.8HIGH
- CVE-2011-3045EG 8.8HIGH
Frequently asked(6)
What is CVE-2022-0185?
When was CVE-2022-0185 disclosed?
Is CVE-2022-0185 actively exploited?
What is the CVSS score of CVE-2022-0185?
Which products are affected by CVE-2022-0185?
How do I remediate CVE-2022-0185?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2022-0185
Is Your Infrastructure Affected by CVE-2022-0185?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.