7.8

CVE-2022-0492

Warnung
Medienbericht
Exploit
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Linux ≫ Linux Kernel Version >= 2.6.24 < 4.9.301
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.266
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.229
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.177
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.97
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.20
Linux ≫ Linux Kernel Version >= 5.16 < 5.16.6
Linux ≫ Linux Kernel Version 5.17 Update rc1
Linux ≫ Linux Kernel Version 5.17 Update rc2
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Redhat ≫ Virtualization Host Version 4.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.2
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 22.04 SwEdition lts
Fedoraproject ≫ Fedora Version 35
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

02.06.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Improper Authentication Vulnerability

Schwachstelle

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.53% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:52
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:52
https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5096
Third Party Advisory
https://www.debian.org/security/2022/dsa-5095
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html
Third Party Advisory
VDB Entry
http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
Third Party Advisory
VDB Entry
http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html
Exploit
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=2051505
Patch
Third Party Advisory
Issue Tracking
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af
Patch
Vendor Advisory
https://security.netapp.com/advisory/ntap-20220419-0002/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0492
US Government Resource