logo

CVE-2022-0185 - Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google's KCTF Containers

ID: d864aec6-3740-530c-a5bf-8586be04b337

STIX ID: report--d864aec6-3740-530c-a5bf-8586be04b337

Feed Name: Will's Root

Threat Score
85/100

Date Published: 2022-01-25

Date Updated: 2026-04-19

Author: Unknown

...
...

This report describes a kernel heap overflow (CVE-2022-0185) in legacy_parse_param affecting Linux kernels since 5.1, demonstrates PoCs and full exploits achieving local privilege escalation and container escape (including an exploit used successfully against a hardened kCTF environment), explains the root cause (unsigned integer underflow permitting infinite overflow into a kmalloc-4k slab), and documents mitigation (a simple bounds-check patch) and exploitation techniques (msg_msg manipulation, FUSE-based userland races, ROP to commit creds and switch namespaces).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.