CVE-2022-0492
published 2022-03-03CVE-2022-0492: A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances…
PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-06-05
Exploited in the wild
EPSS
5.53%
91.9th percentile
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.16.7-1 (bookworm) | linux 5.16.7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 5.16.7-1 | 5.16.7-1 |
| linux | linux_kernel | >= 0 < 4.15.0-173.182 | 4.15.0-173.182 |
| linux | linux_kernel | >= 0 < 5.4.0-105.119 | 5.4.0-105.119 |
| linux | linux_kernel | >= 0 < 4.4.0-222.255 | 4.4.0-222.255 |
| linux | linux_kernel | >= 0 < 4.4.0-227.261 | 4.4.0-227.261 |
| linux | linux_kernel | >= 0 < 4.15.0-180.189 | 4.15.0-180.189 |
| linux | linux_kernel | >= 0 < 4.15.0-173.182 | 4.15.0-173.182 |
| linux | linux_kernel | >= 0 < 5.4.0-117.132 | 5.4.0-117.132 |
| linux | linux_kernel | >= 0 < 5.4.0-105.119 | 5.4.0-105.119 |
| linux | linux_kernel | >= 0 < 5.15.0-37.39 | 5.15.0-37.39 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for writes to the cgroups v1 release_agent file (e.g. /sys/fs/cgroup/*/release_agent) from within container processes, which is the core exploitation primitive for CVE-2022-0492. ↗
- →Detect use of the unshare() syscall from within containers to create new user and cgroup namespaces, a required step for unprivileged container escape via CVE-2022-0492. ↗
- →Alert on cgroupfs mount operations originating from inside a container, especially mounting the memory or RDMA cgroup subsystem, as this is a prerequisite for exploitation. ↗
- →Flag containers running without AppArmor, SELinux, or Seccomp profiles, as these are the configurations vulnerable to container escape via CVE-2022-0492. ↗
- →Detect containers running in the root cgroup of a subsystem (e.g. root RDMA cgroup), as this is required for the release_agent file to be visible and exploitable. ↗
- →Monitor writes to notify_on_release files within cgroupfs from container processes, as enabling this is a required step in the exploitation chain. ↗
- ·Exploitation requires the container to run without AppArmor, SELinux, or Seccomp — containers protected by any of these are not vulnerable to escape via this CVE. ↗
- ·The host must have unprivileged user namespaces enabled (default on recent Ubuntu releases) for the namespace-based exploitation path to work. ↗
- ·Only cgroups v1 is affected; cgroups v2 environments are not vulnerable. ↗
- ·Exploitation requires the container process to run as root (or have CAP_DAC_OVERRIDE), since the release_agent file is owned by root. ↗
- ·The vulnerability is especially dangerous in containerized environments using cgroups v1 when containers are granted elevated capabilities. ↗
- ·Fixed kernel versions include 4.9.301+, 4.14.266+, 4.19.229+, 5.4.177+, 5.10.97+, 5.15.20+, 5.16.6+, and 5.17-rc3+. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Linux Kernel Improper Authentication Vulnerability
cisa·2026-06-02·CVSS 7.8
CVE-2022-0492 [HIGH] CWE-287 Linux Kernel Improper Authentication Vulnerability
Vulnerability: Linux Kernel Improper Authentication Vulnerability
Affected: Linux Kernel
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af ; https://www.kernel.org
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Kernel) — CVE-2022-0492
vendor_oracle·2023-01-15·CVSS 7.8
CVE-2022-0492 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Kernel) — CVE-2022-0492
Oracle Oracle Communications Risk Matrix: Platform (Kernel) vulnerability
CVE: CVE-2022-0492
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
CISA ICS
Hitachi Energy APM Edge
cisa_ics·2022-09-27·CVSS 7.8
[HIGH] Hitachi Energy APM Edge
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge
Last RevisedSeptember 27, 2022
Alert CodeICSA-22-270-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity/public exploits are available
- Vendor: Hitachi Energy
- Equipment: Lumada Asset Performance Management (APM) Edge
- Vulnerabilities: Out-of-Bounds Write and Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow users to escalate privileges from a user account to root.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of APM are affected:
- Lumada
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2022-06-02·CVSS 7.0
CVE-2022-1055 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2021-39713)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges.(CVE-2022-0492)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial
Ubuntu
Linux kernel (BlueField) vulnerabilities
vendor_ubuntu·2022-04-13·CVSS 6.5
CVE-2021-45095 [MEDIUM] Linux kernel (BlueField) vulnerabilities
Title: Linux kernel (BlueField) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-1055)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to other guest
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-04-06·CVSS 6.5
CVE-2021-28713 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-1055)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use
Ubuntu
Linux kernel (Intel IOTG) vulnerabilities
vendor_ubuntu·2022-04-01·CVSS 6.5
CVE-2022-0742 [MEDIUM] Linux kernel (Intel IOTG) vulnerabilities
Title: Linux kernel (Intel IOTG) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Nick Gregory discovered that the Linux kernel incorrectly handled network
offload functionality. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code. (CVE-2022-25636)
Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano
Giuffrida discovered that hardware mitigations added by ARM to their
processors to address Spectre-BTI were insufficient. A local attacker could
potentially use this to expose sensitive information. (CVE-2022-23960)
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of servic
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2022-03-23·CVSS 7.8
CVE-2022-0492 [HIGH] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges.(CVE-2022-0492)
Nick Gregory discovered that the Linux kernel incorrectly handled network
offload functionality. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code.(CVE-2022-25636)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 7.8
CVE-2020-25673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly us
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 7.1
CVE-2022-0435 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that an out-of-bounds (OOB) memory access flaw existed in
the f2fs module of the Linux kernel. A local attacker could use this issue
to cause a denial of service (system crash). (CVE-2021-3506)
Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver
in the Linux kernel did not properly handle some error conditions. A
physically proximate attacker could use this to cause a denial of service
(system crash). (CVE-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 6.5
CVE-2021-43976 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to other guest VMs. An attacker in a driver domain
could use this to cause a denial of service in other guest VMs.
(CVE-2021-28711, CVE-2021-28712, CVE-2021-28713)
Jürgen Groß discovered that the Xen network backend driver in the Linux
kernel did not adequately limit the amount of
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 6.5
CVE-2021-45480 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to other guest VMs. An attacke
Microsoft
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw under certain circumstances allows the use of the cgroups v1 release_age
vendor_msrc·2022-03-08·CVSS 7.8
CVE-2022-0492 [HIGH] CWE-862 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw under certain circumstances allows the use of the cgroups v1 release_age
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw under certain circumstances allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for mo
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2022-02-22·CVSS 4.6
CVE-2022-24448 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver
in the Linux kernel did not properly handle some error conditions. A
physically proximate attacker could use this to cause a denial of service
(system crash). (CVE-2021-43976)
Wenqing Liu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate inode types while performing garbage
collection. An attacker could use this to const
Red Hat
kernel: cgroups v1 release_agent feature may allow privilege escalation
vendor_redhat·2022-02-07·CVSS 7.8
CVE-2022-0492 [HIGH] CWE-862 kernel: cgroups v1 release_agent feature may allow privilege escalation
kernel: cgroups v1 release_agent feature may allow privilege escalation
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Statement: In the OpenShift Container Platform (OCP) the container escape and privilege escalation caused by the CVE-2022-0492 vulnerability are blocked by
Debian
CVE-2022-0492: linux - A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in th...
vendor_debian·2022·CVSS 7.8
CVE-2022-0492 [HIGH] CVE-2022-0492: linux - A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in th...
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Scope: local
bookworm: resolved (fixed in 5.16.7-1)
bullseye: resolved (fixed in 5.10.103-1)
forky: resolved (fixed in 5.16.7-1)
sid: resolved (fixed in 5.16.7-1)
trixie: resolved (fixed in 5.16.7-1)
Kernel
security, lsm: Introduce security_create_user_ns()
kernel_security·2022-08-15
CVE-2022-0492 security, lsm: Introduce security_create_user_ns()
security, lsm: Introduce security_create_user_ns()
User namespaces are an effective tool to allow programs to run with
permission without requiring the need for a program to run as root. User
namespaces may also be used as a sandboxing technique. However, attackers
sometimes leverage user namespaces as an initial attack vector to perform
some exploit. [1,2,3]
While it is not the unprivileged user namespace functionality, which
causes the kernel to be exploitable, users/administrators might want to
more granularly limit or at least monitor how various processes use this
functionality, while vulnerable kernel subsystems are being patched.
Preventing user namespace already creation comes in a few of forms in
order of granularity:
1. /proc/sys/user/max_user_namespaces sysctl
2. Distro spec
OSV
Kernel Live Patch Security Notice
osv·2022-06-02·CVSS 7.0
CVE-2021-39713 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that a race condition existed in the network scheduling
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2021-39713)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges.(CVE-2022-0492)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code.(CVE-
OSV
linux-bluefield vulnerabilities
osv·2022-04-13·CVSS 6.5
CVE-2022-1055 [MEDIUM] linux-bluefield vulnerabilities
linux-bluefield vulnerabilities
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-1055)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to other guest VMs. An attacker in a driver domain
could use this to cause a denial of service i
OSV
linux-azure-5.13, linux-oracle-5.13 vulnerabilities
osv·2022-04-06·CVSS 6.5
CVE-2022-23222 [MEDIUM] linux-azure-5.13, linux-oracle-5.13 vulnerabilities
linux-azure-5.13, linux-oracle-5.13 vulnerabilities
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-1055)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022
OSV
linux-intel-5.13 vulnerabilities
osv·2022-04-01·CVSS 6.5
CVE-2022-25636 [MEDIUM] linux-intel-5.13 vulnerabilities
linux-intel-5.13 vulnerabilities
Nick Gregory discovered that the Linux kernel incorrectly handled network
offload functionality. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code. (CVE-2022-25636)
Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano
Giuffrida discovered that hardware mitigations added by ARM to their
processors to address Spectre-BTI were insufficient. A local attacker could
potentially use this to expose sensitive information. (CVE-2022-23960)
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Max Kellerm
OSV
Kernel Live Patch Security Notice
osv·2022-03-23·CVSS 7.8
CVE-2022-0492 [HIGH] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges.(CVE-2022-0492)
Nick Gregory discovered that the Linux kernel incorrectly handled network
offload functionality. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code.(CVE-2022-25636)
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gcp-5.4, linux-gke, lnux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4
osv·2022-03-22·CVSS 6.5
[MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gcp-5.4, linux-gke, lnux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-azure-fde, linux-gcp, linux-gcp-5.4, linux-gke, lnux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to other guest VMs. An attacker in a driver domain
could use this to cause a denial of service
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-hwe, linux-gcp, linux-gcp-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2022-03-22·CVSS 7.1
CVE-2022-0492 [HIGH] linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-hwe, linux-gcp, linux-gcp-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-hwe, linux-gcp, linux-gcp-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that an out-of-bounds (OOB) memory access flaw existed in
the f2fs module of the Linux kernel. A local attacker could use this issue
to cause a denial of service (system crash). (CVE-2021-3506)
Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver
in the Linux kernel did not properly handle some error conditions. A
physica
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-03-22·CVSS 7.8
CVE-2022-0492 [HIGH] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
It was discovered that the aufs file system in the Linux kernel did not
properly restrict mount namespaces, when mounted with the non-default
allow_userns option set. A local attacker could use this to gain
administrative privileges. (CVE-2016-2853)
It was discovered that the aufs file system in the Linux kernel did not
properly maintain POSIX ACL xattr data, when mounted with the non-default
allow_userns option. A local attacker could possibly use this to gain
elevated privileges. (CVE
OSV
linux, linux-aws, linux-aws-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities
osv·2022-03-22·CVSS 6.5
CVE-2022-23222 [MEDIUM] linux, linux-aws, linux-aws-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities
linux, linux-aws, linux-aws-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to
OSV
CVE-2022-0492: A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1
osv·2022-03-03·CVSS 7.8
CVE-2022-0492 [HIGH] CVE-2022-0492: A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
OSV
linux-oem-5.14 vulnerabilities
osv·2022-02-22·CVSS 4.6
CVE-2022-0492 [MEDIUM] linux-oem-5.14 vulnerabilities
linux-oem-5.14 vulnerabilities
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver
in the Linux kernel did not properly handle some error conditions. A
physically proximate attacker could use this to cause a denial of service
(system crash). (CVE-2021-43976)
Wenqing Liu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate inode types while performing garbage
collection. An attacker could use this to construct a malicious f2fs image
that, when mounted and operated on, could cause a
VulnCheck
Linux Kernel Improper Authentication
vulncheck·2022·CVSS 7.8
CVE-2022-0492 [HIGH] Linux Kernel Improper Authentication
Linux Kernel Improper Authentication
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Affected: Linux Kernel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://securelist.com/container-attack-vectors/120010/
Exploit PoC: https://vulncheck.com/xdb/163b6fa2305e; https://vulncheck.com/xdb/39e32141d838; https://vulncheck.com/xdb/f823d8588982; https://vulncheck.com/xdb/4ce10a8b48ed; https://vulncheck.com/xdb/0cb6f125b86f
Hackernews
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
blogs_hackernews·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
It got stupid again.
The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and come back worse. Cheap hackers get better toys. AI starts breaking real systems. Great.
Read the whole thing before it ruins your week anyway.
Cisco has released fixes to address a high-severity security flaw in Unified Communications Manager (CVE-2026-20230, CVSS score: 8.6) that could allow an unauthe
Bleepingcomputer
CISA warns of active attacks exploiting Android, Linux bugs
blogs_bleepingcomputer·2026-06-03·CVSS 7.8
CVE-2025-48595 [HIGH] CISA warns of active attacks exploiting Android, Linux bugs
## CISA warns of active attacks exploiting Android, Linux bugs
## Bill Toulas
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
According to Google’s recent security bulletin , the security issue impacts Android 14 through 16, and requires no user interaction to exploit.
Google indicated that CVE-2025-48595 may be under limited targeted exploitation in the wild, but provided no specific details about the activity or technical information
Securelist
Containers on fire: from container escapes to supply chain attacks
blogs_securelist·2026-06-01
CVE-2019-5736 Containers on fire: from container escapes to supply chain attacks
Alexander Chudnov
Table of Contents
Introduction
Principles of containerization
Current attack vectors
Exploiting host system vulnerabilities
Malicious actions inside the container
Container escape
Privileged containers
CAP_SYS_ADMIN
CAP_SYS_MODULE
CAP_SYS_PTRACE
CAP_NET_ADMIN
Exploitation of orchestration APIs
Supply chain attacks
Takeaways
Authors
Alexander Chudnov
## Introduction
Modern infrastructures universally rely on containerization to deploy applications, scale services, and build cloud platforms. The use of Docker, Kubernetes, and similar technologies has become the corporate standard for efficient automation. However, as containers grow in popularity, so does the interest of malicious actors — a trend we actively track in our research into advanced cyberthrea
Unit42
Container Breakouts: Escape Techniques in Cloud Environments
blogs_unit42·2024-07-18·CVSS 8.6
[HIGH] Container Breakouts: Escape Techniques in Cloud Environments
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Container Breakouts: Escape Techniques in Cloud Environments
Yosef Yaakov
Bar Ben-Michael
Published: July 18, 2024
Cloud Cybersecurity Research
Threat Research
Cloud infrastructure
Container
Container escape
Container security
Docker
Kubernetes
## Executive Summary
This article reviews container escape techniques, assesses their possible impact and reveals how to detect these escapes from the perspective of endpoint detection and response (EDR).
As cloud services rise in popularity, so does the use of containers, which have become an integrated part of cloud infrastructure. Although containers provide many advantages, they are also susceptible to attack techniques like container escapes.
Many conta
Unit42
Container Breakouts: Escape Techniques in Cloud Environments
blogs_unit42·2024-07-18·CVSS 8.6
[HIGH] Container Breakouts: Escape Techniques in Cloud Environments
## Executive Summary
This article reviews container escape techniques, assesses their possible impact and reveals how to detect these escapes from the perspective of endpoint detection and response (EDR).
As cloud services rise in popularity, so does the use of containers, which have become an integrated part of cloud infrastructure. Although containers provide many advantages, they are also susceptible to attack techniques like container escapes.
Many containers are internet-facing, which poses an even greater security risk. For example, an external attacker who has gained low-privilege access to a container will attempt to escape it through a variety of methods that include exploiting misconfigurations and vulnerabilities.
Container escapes are a notable security risk for organizatio
Sentinelone
SentinelOne® Enhances Cloud Security with Snyk
blogs_sentinelone·2023-11-09
SentinelOne® Enhances Cloud Security with Snyk
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management Application & OS Vulnerability Management
S
Unit42
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
blogs_unit42·2022-03-03·CVSS 7.8
CVE-2022-0492 [HIGH] New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
Yuval Avrahami
Published: March 3, 2022
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
Containers
CVE-2022-0492
Linux
## Executive Summary
On Feb. 4, Linux announced CVE-2022-0492 , a new privilege escalation vulnerability in the kernel. CVE-2022-0492 marks a logical bug in control groups ( cgroups ), a Linux feature that is a fundamental building block of containers. The issue stands out as one of the simplest Linux privilege escalations discovered in recent times: The Linux kernel mistakenly exposed a privileged operation to unprivileged users.
Fortunately, the default security hardenings in most container e
Unit42
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
blogs_unit42·2022-03-03·CVSS 7.8
CVE-2022-0492 [HIGH] New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?
## Executive Summary
On Feb. 4, Linux announced CVE-2022-0492, a new privilege escalation vulnerability in the kernel. CVE-2022-0492 marks a logical bug in control groups (cgroups), a Linux feature that is a fundamental building block of containers. The issue stands out as one of the simplest Linux privilege escalations discovered in recent times: The Linux kernel mistakenly exposed a privileged operation to unprivileged users.
Fortunately, the default security hardenings in most container environments are enough to prevent container escape. Containers running with AppArmor, SELinux or Seccomp are protected. That being said, if you run containers without best practice hardenings, or with additional privileges, you may be at risk. The "Am I Affected?" section lists vulnerable container co
Sentinelone
SentinelOne® Enhances Cloud Security with Snyk
blogs_sentinelone
SentinelOne® Enhances Cloud Security with Snyk
# SentinelOne® Enhances Cloud Security with Snyk
Company integrates Singularity™ Cloud Workload Security with the Snyk Developer Security Platform, helping customers secure cloud-native applications from build time to runtime
BOCA RATON, FL – November 9, 2023 – Prioritizing which vulnerabilities to fix is a challenge for software developers, and the complexities of modern apps and the software supply chain has only made things more difficult. SentinelOne (NYSE: S), a global leader in AI security, is partnering with Snyk, the leader in developer security, to ease the burden. The company today announced the integration of Singularity Cloud Workload Security, its real-time Cloud Workload Protection Platform (CWPP), with the Snyk Developer Security Platform.
The integration will correlate t
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Goldilocks Isolation: High Performance VMs with Edera
arxiv_fulltext·2025-01-08
Goldilocks Isolation: High Performance VMs with Edera
## Abstract
Organizations run applications on cloud infrastructure shared between multiple users and organizations.
Popular tooling for this shared infrastructure, including Docker and Kubernetes, supports such multi-tenancy through the use of operating system virtualization.
With operating system virtualization (known as containerization), multiple applications share the same kernel, reducing the runtime overhead.
However, this shared kernel presents a large attack surface and has led to a proliferation of container escape attacks in which a kernel exploit lets an attacker escape the isolation of operating system virtualization to access other applications or the operating system itself.
To address this, some systems have proposed a return to hypervisor virtualization for stronger isolat
arXiv
Comparing Security and Efficiency of WebAssembly and Linux Containers in Kubernetes Cloud Computing
arxiv_fulltext·2024-11-02
Comparing Security and Efficiency of WebAssembly and Linux Containers in Kubernetes Cloud Computing
minipage
*Zusammenfassung
In dieser Studie wird das Potenzial von WebAssembly als sicherere und effizientere Alternative zu Linux-Containern für die Ausführung von nicht vertrauenswürdigem Code im Cloud-Computing mit Kubernetes untersucht.
Insbesondere werden die Auswirkungen dieses Wechsels auf Sicherheit und Leistung bewertet.
Sicherheitsanalysen zeigen, dass sowohl Linux-Container als auch WebAssembly bei der Ausführung von nicht vertrauenswürdigem Code Angriffsflächen bieten, wobei diese Angriffsfläche bei WebAssembly aufgrund einer zusätzlichen Isolierungsschicht geringer ausfällt.
Die Leistungsanalyse zeigt außerdem, dass WebAssembly ineffizientere Ausführung als nativer Code bedingt und hohe Kaltstartzeiten hat, die bei lang laufenden Berechnungen vernachlässigbar sein könnten.
We
arXiv
Towards a Security Stress-Test for Cloud Configurations
arxiv_fulltext·2022-06-07
Towards a Security Stress-Test for Cloud Configurations
Towards a Security Stress-Test for Cloud Configurations
This work has received funding from the European Union under the H2020 grant 952647 (AssureMOSS).
1st Francesco Minna
Vrije Universiteit Amsterdam (NL)
[email protected]
2nd Fabio Massacci
University of Trento (IT)
Vrije Universiteit Amsterdam (NL)
[email protected]
3rd Katja Tuma
Vrije Universiteit Amsterdam (NL)
[email protected]
## Abstract
Securing cloud configurations is an elusive task, which is left up to system administrators who have to base their decisions on ``trial and error'' experimentations or by observing good practices (e.g., CIS Benchmarks).
We propose a knowledge, AND/OR, graphs approach to model cloud deployment security objects and vulnerabilities. In this way, we can capture relationships between configura
CTF
insane / README
ctf_writeups
insane / README
---
layout: default
title: Insane Machines
parent: Machines
nav_order: 4
description: "25+ Insane HTB machine writeups with walkthroughs"
permalink: /machines/insane/
---
# HackTheBox INSANE Difficulty Machines - Complete Reference
> Exhaustive list of ALL known retired Insane-rated HTB machines with key techniques and writeup links.
---
## Linux Insane Machines
| # | Machine | OS | Key Techniques | One-Line Summary | Writeup Links |
|---|---------|----|----|------|------|
| 1 | **Brainfuck** | Linux | WordPress plugin exploit, Vigenere cipher, LXD privesc | Chain WP auth bypass with crypto analysis and container group abuse for root | [0xdf](https://0xdf.gitlab.io/2022/05/16/htb-brainfuck.html), [Medium](https://sparshjazz.medium.com/hackthebox-brainfuck-difficulty-insane-53f0fe650f5
CTF
Carpediem / README
ctf_writeups
Carpediem / README
# Carpediem
## Summary
This is a hard box with many steps, but each step is relatively simple.
Nmap finds SSH and an Nginx web server on port `80`. The web server is just a countdown page so we scan for virtual hosts and find `portal.carpediem.htb`, which is a motorcycle store. We find LFI and SQLi attacks, but neither give us any useful information. There is also an admin page at `/admin`. We create an account and notice a strange parameter in the POST request that is sent when we edit our profile. Changing that parameter and then going to `/admin` gives us access to the admin portal. We can upload a profile picture, so we create a legitimate PNG image and then embed PHP code in the metadata of the image. This gives a reverse shell into a Docker container.
Inside the Docker container'
http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.htmlhttp://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlhttp://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2051505https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02afhttps://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20220419-0002/https://www.debian.org/security/2022/dsa-5095https://www.debian.org/security/2022/dsa-5096http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.htmlhttp://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlhttp://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2051505https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02afhttps://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20220419-0002/https://www.debian.org/security/2022/dsa-5095https://www.debian.org/security/2022/dsa-5096https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0492
2022-03-03
Published
2026-06-02
Added to CISA KEV
Exploited in the wild