CVE-2022-0492
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linuxmint, Linux Kernel, Red Hat, Red Os
- Netapp h300s Firmware
- All versions
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 5.5% (92th percentile)
- Weakness
- CWE-862, CWE-287
- NVD status
- Analyzed
- Published
- 2022-03-03
CVE-2022-0492 at NVD
11 known exploits for CVE-2022-0492
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Authentication in Linux Linux_Kernel
Exploit for Race Condition in Canonical Ubuntu_Linux
Exploit for OS Command Injection in Docker
Docker cgroups Container Escape Exploit
Docker cgroups Container Escape
Exploit for Improper Authentication in Linux Linux_Kernel
Exploit for Improper Input Validation in Imagemagick
Exploit for Improper Authentication in Linux Linux_Kernel
Exploit for Improper Authentication in Linux Linux_Kernel
Exploit for Improper Authentication in Linux Linux_Kernel
Docker cgroups Container Escape