Database/Kernel, userspace & hypervisor
Linux kernel (fs_context): Heap overflow in legacy filesystem parameter handling
Impact
Heap overflow in legacy filesystem parameter handling; escapes unprivileged containers to host root [KEV]
Who can reach it
Any tenant process in a container with a user namespace
What to do
Livepatchable; otherwise drain + reboot. Mitigate by disabling unprivileged user namespaces
Fleet impact
How widespread
Universal - kernel 5.1 through 5.16.1; exploitable wherever unprivileged user namespaces are on, which is the default on Ubuntu GPU images
Cost to remediate
node-reboot - kernel upgrade; the only no-reboot mitigation is disabling unprivileged user namespaces, which breaks rootless/Podman-style tenant workflows
Why it hits the whole fleet
Heap overflow in fs_context gives a container-confined attacker full host root, demonstrated as a Kubernetes container escape on GKE/EKS/AKS-class engines - one tenant image compromises the whole node and its co-tenants
References
Related entries
- Linux i915 GPU kernel driver (GTT TLB handling): Stale GPU TLB entries let the GPU keep reading physical pages afterCVE-2022-0330 · Linux i915 GPU kernel driver (GTT TLB handling)High
- Linux kernel (pipe): Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, inclCVE-2022-0847 · Linux kernel (pipe)High
- Linux kernel: out-of-bounds write in watch_queue filters lets a local user gain rootCVE-2022-0995 · Linux kernel watch_queue event notification subsystem (filter handling)High
- Linux kernel io_uring: missing work_flags identity types cause bad refcounts and a double freeCVE-2022-2327 · Linux kernel io_uring (per-operation identity reference counting)High
- Linux kernel (net/sched cls_route): Use-after-free in the cls_route filterCVE-2022-2588 · Linux kernel (net/sched cls_route)High
- Xen on AMD-Vi - unity map handling on device reassignment: AMD-Vi unity mappings are not correctly torn down orCVE-2022-26358 · Xen on AMD-Vi - unity map handling on device reassignmentHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.