Severity
7.8HIGH
EPSS
5.1%
top 10.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateJan 15

Description

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages27 packages

NVDlinux/linux_kernel2.6.244.9.301+7
Debianlinux< 5.10.103-1+3
Ubuntulinux< 4.15.0-173.182+3
Ubuntulinux-aws< 4.15.0-1124.133+4
Ubuntulinux-kvm< 4.15.0-1110.113+1

Also affects: Debian Linux 10.0, 11.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 20.04, 22.04, Enterprise Linux 8.0, 8.2, 8.1, Fedora 35

Patches

🔴Vulnerability Details

10
Kernel
security, lsm: Introduce security_create_user_ns()2022-08-15
OSV
linux-bluefield vulnerabilities2022-04-13
OSV
Kernel Live Patch Security Notice2022-03-23
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-hwe, linux-gcp, linux-gcp-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2022-03-22
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22

🔍Detection Rules

1
Elastic
Docker Release File Creation

📋Vendor Advisories

14
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Kernel) — CVE-2022-04922023-01-15
Ubuntu
Kernel Live Patch Security Notice2022-06-02
Ubuntu
Linux kernel (BlueField) vulnerabilities2022-04-13
Ubuntu
Linux kernel vulnerabilities2022-04-06
Ubuntu
Linux kernel (Intel IOTG) vulnerabilities2022-04-01

🕵️Threat Intelligence

2
Unit42
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?2022-03-03
Unit42
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?2022-03-03