Vulnerabilities

CVE-2022-0492

Linux Kernel Improper Authentication Vulnerability

Actively exploited (CISA KEV) High 7.8 CVSS 3.1

Description

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

Description as published by the source, in English.

Key facts

Published
2022-03-03
Last modified
2026-06-17
Assigned by
secalert@redhat.com
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Scored by
nvd@nist.gov (NVD Primary)
Probability of exploitation
5.5 % higher than 92 % of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Yes, see references

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-02, with a remediation deadline of 2026-06-05 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Canonical Ubuntu Linux 14.04 Affected
Canonical Ubuntu Linux 16.04 Affected
Canonical Ubuntu Linux 18.04 Affected
Canonical Ubuntu Linux 20.04 Affected
Canonical Ubuntu Linux 22.04 Affected
Debian Debian Linux 10.0 Affected
Debian Debian Linux 11.0 Affected
Debian Debian Linux 9.0 Affected
Fedoraproject Fedora 35 Affected
Linux Linux Kernel 5.17 Affected
Linux Linux Kernel ≥ 2.6.24, < 4.9.301 Affected
Linux Linux Kernel ≥ 4.10, < 4.14.266 Affected
Linux Linux Kernel ≥ 4.15, < 4.19.229 Affected
Linux Linux Kernel ≥ 4.20, < 5.4.177 Affected
Linux Linux Kernel ≥ 5.11, < 5.15.20 Affected
Linux Linux Kernel ≥ 5.16, < 5.16.6 Affected
Linux Linux Kernel ≥ 5.5, < 5.10.97 Affected
Netapp Bootstrap Os all versions listed Affected
Netapp H300s all versions listed Not affected
Netapp H300s Firmware all versions listed Affected
Netapp H410c all versions listed Not affected
Netapp H410c Firmware all versions listed Affected
Netapp H410s all versions listed Not affected
Netapp H410s Firmware all versions listed Affected
Netapp H500s all versions listed Not affected
Netapp H500s Firmware all versions listed Affected
Netapp H700s all versions listed Not affected
Netapp H700s Firmware all versions listed Affected
Netapp Hci Compute Node all versions listed Not affected
Netapp Solidfire & Hci Management Node all versions listed Affected
Netapp Solidfire, Enterprise Sds & Hci Storage Node all versions listed Affected
Redhat Codeready Linux Builder 8.0 Affected
Redhat Codeready Linux Builder 8.2 Affected
Redhat Codeready Linux Builder For Power Little Endian 8.0 Affected
Redhat Codeready Linux Builder For Power Little Endian 8.2 Affected
Redhat Enterprise Linux 8.0 Affected
Redhat Enterprise Linux Eus 8.2 Affected
Redhat Enterprise Linux For Ibm Z Systems 8.0 Affected
Redhat Enterprise Linux For Ibm Z Systems Eus 8.0 Affected
Redhat Enterprise Linux For Power Little Endian 8.0 Affected
Redhat Enterprise Linux For Power Little Endian Eus 8.0 Affected
Redhat Enterprise Linux For Real Time For Nfv Tus 8.0 Affected
Redhat Enterprise Linux For Real Time For Nfv Tus 8.2 Affected
Redhat Enterprise Linux For Real Time Tus 8.0 Affected
Redhat Enterprise Linux For Real Time Tus 8.2 Affected
Redhat Enterprise Linux Server Aus 8.2 Affected
Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions 8.1 Affected
Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions 8.2 Affected
Redhat Enterprise Linux Server Tus 8.2 Affected
Redhat Enterprise Linux Server Update Services For Sap Solutions 8.1 Affected
Redhat Enterprise Linux Server Update Services For Sap Solutions 8.2 Affected
Redhat Virtualization Host 4.0 Affected

Weakness type

Attack techniques

Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.

  • T1040: Network Sniffing credential-access, discovery
  • T1134: Access Token Manipulation stealth, privilege-escalation
  • T1185: Browser Session Hijacking collection
  • T1211: Exploitation for Stealth stealth
  • T1505.003: Web Shell persistence
  • T1542.002: Component Firmware stealth, persistence
  • T1548: Abuse Elevation Control Mechanism privilege-escalation
  • T1550.001: Application Access Token lateral-movement
  • T1556: Modify Authentication Process defense-impairment, persistence, credential-access
  • T1557: Adversary-in-the-Middle credential-access, collection
  • T1563: Remote Service Session Hijacking lateral-movement

References

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities