CVE-2022-0492 KEV
7.8
HIGH · CVSS 3.1 · EPSS 5.5% (pctl 93)
Patch first
On CISA KEV — known exploited in the wild, due 2026-06-05.
Description
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.53% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | yes — remediate by 2026-06-05 |
| Public exploit | none known |
| Published | 2022-03-03 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Linux Kernel Improper Authentication Vulnerability |
|---|---|
| Added | 2026-06-02 |
| Due | 2026-06-05 |
| Vendor / product | Linux / Kernel |
| Ransomware use | none reported |
Affected (33)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| fedoraproject | fedora |
| linux | linux kernel |
| netapp | bootstrap os |
| netapp | h300s |
| netapp | h300s firmware |
| netapp | h410c |
| netapp | h410c firmware |
| netapp | h410s |
| netapp | h410s firmware |
| netapp | h500s |
| netapp | h500s firmware |
| netapp | h700s |
| netapp | h700s firmware |
| netapp | hci compute node |
| netapp | solidfire \& hci management node |
| netapp | solidfire\, enterprise sds \& hci storage node |
| redhat | codeready linux builder |
| redhat | codeready linux builder for power little endian |
| redhat | enterprise linux |
| redhat | enterprise linux eus |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for ibm z systems eus |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux for power little endian eus |
| redhat | enterprise linux for real time for nfv tus |
| redhat | enterprise linux for real time tus |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server for power little endian update services for sap solutions |
| redhat | enterprise linux server tus |
| redhat | enterprise linux server update services for sap solutions |
| redhat | virtualization host |
References
- http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
- http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2051505
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://security.netapp.com/advisory/ntap-20220419-0002/
- https://www.debian.org/security/2022/dsa-5095
- https://www.debian.org/security/2022/dsa-5096
- http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
- http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2051505
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://security.netapp.com/advisory/ntap-20220419-0002/
- https://www.debian.org/security/2022/dsa-5095
- https://www.debian.org/security/2022/dsa-5096
→ the Explorer · watch your stack · NVD