CVE-2022-0492
kernel
Published 3 Mar 2022 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 2 Jun 2026, with a remediation deadline of 5 Jun 2026 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
References
- packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html · Exploit, VDB Entry
- bugzilla.redhat.com/show_bug.cgi?id=2051505 · Issue Tracking, Patch, Third Party Advisory
- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af · Patch, Vendor Advisory
- lists.debian.org/debian-lts-announce/2022/03/msg00011.html · Mailing List, Third Party Advisory
- lists.debian.org/debian-lts-announce/2022/03/msg00012.html · Mailing List, Third Party Advisory
- security.netapp.com/advisory/ntap-20220419-0002/ · Third Party Advisory
- www.debian.org/security/2022/dsa-5095 · Third Party Advisory
- www.debian.org/security/2022/dsa-5096 · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0492 · US Government Resource