CVE-2022-0492

Advisory lineage Upstream: 0 Downstream: 64
Modified
Published: 03 Mar 2022, 00:00
Last modified:02 Jun 2026, 19:58

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
5.24% LOW
5% probability -1.29%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

03 Mar 2022, 00:00
Published
Vulnerability first disclosed
02 Jun 2026, 00:00
Added to CISA KEV
Linux Kernel Improper Authentication Vulnerability
02 Jun 2026, 19:58
Last Modified
Vulnerability information updated
05 Jun 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 5.24% Percentile: 90%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-862Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 20.04 | 22.04

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    35

  • linuxlinux_kernel

    ≥ 2.6.24, < 4.9.301 | ≥ 4.10, < 4.14.266 | ≥ 4.15, < 4.19.229 | ≥ 4.20, < 5.4.177 | ≥ 5.5, < 5.10.97 | ≥ 5.11, < 5.15.20 | ≥ 5.16, < 5.16.6 | 5.17:rc1 | 5.17:rc2

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • netapphci_compute_node_firmware

    na

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire\,_enterprise_sds_\&_hci_storage_node

    na

  • redhatcodeready_linux_builder

    8.0 | 8.2

  • redhatcodeready_linux_builder_for_power_little_endian

    8.0 | 8.2

  • redhatenterprise_linux

    8.0

  • redhatenterprise_linux_eus

    8.2

  • redhatenterprise_linux_for_ibm_z_systems

    8.0

  • redhatenterprise_linux_for_ibm_z_systems_eus

    8.0

  • redhatenterprise_linux_for_power_little_endian

    8.0

  • redhatenterprise_linux_for_power_little_endian_eus

    8.0

  • redhatenterprise_linux_for_real_time_for_nfv_tus

    8.0 | 8.2

  • redhatenterprise_linux_for_real_time_tus

    8.0 | 8.2

  • redhatenterprise_linux_server_aus

    8.2

  • redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

    8.1 | 8.2

  • redhatenterprise_linux_server_tus

    8.2

  • redhatenterprise_linux_server_update_services_for_sap_solutions

    8.1 | 8.2

  • redhatvirtualization_host

    4.0

References (11)