kernel: fs_context: heap overflow in legacy parameter handling
Published Feb 11, 2022 ·Due Sep 11, 2024
8.4
HIGHCVSS 3.1
EPSS 25.15%
Description
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version 8.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- ≥ 5.1 · < 5.4.173
- ≥ 5.5 · < 5.10.93
- ≥ 5.11 · < 5.15.16
- ≥ 5.16 · < 5.16.2
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
-
- Version 8.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | n/a |
|
Red Hat Enterprise Linux 8
kernel-0:4.18.0-348.12.2.el8_5
Fixed · RHSA-2022:0188
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-348.12.2.rt7.143.el8_5
Fixed · RHSA-2022:0176
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2022:0232
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.34.2.el8_4
Fixed · RHSA-2022:0186
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.34.2.rt7.107.el8_4
Fixed · RHSA-2022:0187
Red Hat Enterprise Linux 8.4 Extended Update Support
kpatch-patch
Fixed · RHSA-2022:0231
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.4.10-202202081536_8.5
Fixed · RHSA-2022:0540
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-348.12.2.el8_5 | Fixed | RHSA-2022:0188 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-348.12.2.rt7.143.el8_5 | Fixed | RHSA-2022:0176 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2022:0232 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.34.2.el8_4 | Fixed | RHSA-2022:0186 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.34.2.rt7.107.el8_4 | Fixed | RHSA-2022:0187 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kpatch-patch | Fixed | RHSA-2022:0231 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.4.10-202202081536_8.5 | Fixed | RHSA-2022:0540 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 8.4 GA onwards. Previous Red Hat Enterprise Linux versions are not affected.
Red Hat mitigation
On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-0185 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2040358 Issue Tracking
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de2 x_refsource_MISCMailing ListPatch
- https://github.com/Crusaders-of-Rust/CVE-2022-0185 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0185
- https://security.netapp.com/advisory/ntap-20220225-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0185 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2022-0185
- https://www.openwall.com/lists/oss-security/2022/01/18/7 x_refsource_MISCMailing ListPatchThird Party Advisory
- https://www.willsroot.io/2022/01/cve-2022-0185.html x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0185 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2040358 | Issue Tracking | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de2 | x_refsource_MISCMailing ListPatch | |
| https://github.com/Crusaders-of-Rust/CVE-2022-0185 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0185 | ||
| https://security.netapp.com/advisory/ntap-20220225-0003/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0185 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2022-0185 | ||
| https://www.openwall.com/lists/oss-security/2022/01/18/7 | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| https://www.willsroot.io/2022/01/cve-2022-0185.html | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.