Executive brief
A heap-based buffer overflow vulnerability exists in the legacy_parse_param function within the Linux kernel's Filesystem Context functionality. The flaw occurs during the verification of parameter lengths when falling back to legacy handling for filesystems that do not support the Filesystem Context API. A local attacker can exploit this to escalate privileges, particularly in environments where unprivileged user namespaces are enabled.
Affected products
- Linux Linux Kernel
Timeline
- 2022-01-18: disclosed: Initial disclosure on oss-security mailing list
- 2024-08-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-11: other: CISA KEV due date for remediation