Database/Kernel, userspace & hypervisor
Linux kernel (fs_context): Heap overflow in legacy filesystem parameter handling
Impact
Heap overflow in legacy filesystem parameter handling; escapes unprivileged containers to host root [KEV]
Who can reach it
Any tenant process in a container with a user namespace
What to do
Livepatchable; otherwise drain + reboot. Mitigate by disabling unprivileged user namespaces
Fleet impact
How widespread
Universal - kernel 5.1 through 5.16.1; exploitable wherever unprivileged user namespaces are on, which is the default on Ubuntu GPU images
Cost to remediate
node-reboot - kernel upgrade; the only no-reboot mitigation is disabling unprivileged user namespaces, which breaks rootless/Podman-style tenant workflows
Why it hits the whole fleet
Heap overflow in fs_context gives a container-confined attacker full host root, demonstrated as a Kubernetes container escape on GKE/EKS/AKS-class engines - one tenant image compromises the whole node and its co-tenants
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.