PT-2022-1533 · Linux+10 · Linux Kernel+10

Kevin Wang

+1

·

Published

2022-01-20

·

Updated

2026-06-02

·

CVE-2022-0492

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions 2.6.24 through 4.9.300 Linux Kernel versions 4.14.0 through 4.14.265 Linux Kernel versions 4.19.0 through 4.19.228 Linux Kernel versions 5.4.0 through 5.4.176 Linux Kernel versions 5.10.0 through 5.10.96 Linux Kernel versions 5.15.0 through 5.15.25 Linux Kernel versions 5.16.0 through 5.16.11
Description A flaw exists in the cgroup release agent write function within the kernel/cgroup/cgroup-v1.c file of the Linux kernel. This issue stems from a lack of privilege control when configuring the release agent feature of cgroups v1 (Control Groups v1), which are Linux functions used to limit, account for, and isolate resource usage for sets of processes. Under certain circumstances, this allows an attacker to bypass namespace isolation, escape from an isolated container, and escalate privileges to root access on the host system. This issue has been actively exploited in real-world incidents to achieve container escapes and lateral movement to host systems.
Recommendations Update the Linux Kernel to versions 4.9.301, 4.14.266, 4.19.229, 5.4.177, 5.10.97, 5.15.26, or 5.16.12. Enable AppArmor or SELinux to prevent container escape. Enable Seccomp to mitigate the risk of exploitation.

Exploit

Fix

DoS

LPE

Missing Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

ALSA-2022:0825
ALSA-2024_2394
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2022-1221
ALT-PU-2022-1223
ALT-PU-2022-1239
ALT-PU-2022-1289
ALT-PU-2022-1297
ALT-PU-2022-1298
ALT-PU-2022-1300
ALT-PU-2022-1301
ALT-PU-2022-1370
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2022-1428
ALT-PU-2022-1432
ALT-PU-2022-1441
ALT-PU-2022-1467
ALT-PU-2022-1540
ALT-PU-2022-2096
ALT-PU-2023-4894
AZL-8966
BDU:2022-00737
CESA-2022_0819
CESA-2022_0825
CESA-2022_0849
CESA-2022_4642
CVE-2022-0492
DLA-2940-1
DLA-2941-1
DSA-5095-1
DSA-5096-1
ELSA-2022-0825
ELSA-2022-4642
ELSA-2022-9141
ELSA-2022-9142
ELSA-2022-9147
ELSA-2022-9148
ELSA-2022-9179
ELSA-2022-9180
ELSA-2022-9244
ELSA-2022-9245
ELSA-2022-9313
ELSA-2022-9314
ELSA-2022-9667
ELSA-2022-9781
LSN-0085-1
LSN-0086-1
MGASA-2022-0062
MGASA-2022-0063
OESA-2022-1539
OPENSUSE-SU-2022:0755-1
OPENSUSE-SU-2022:0760-1
OPENSUSE-SU-2022:0768-1
OPENSUSE-SU-2022_0755-1
OPENSUSE-SU-2022_0760-1
OPENSUSE-SU-2022_0768-1
RHSA-2022:0819
RHSA-2022:0820
RHSA-2022:0821
RHSA-2022:0823
RHSA-2022:0825
RHSA-2022:0849
RHSA-2022:0851
RHSA-2022:0925
RHSA-2022:0958
RHSA-2022:1413
RHSA-2022:1417
RHSA-2022:1418
RHSA-2022:1455
RHSA-2022:2186
RHSA-2022:2189
RHSA-2022:2211
RHSA-2022:4642
RHSA-2022:4644
RHSA-2022:4655
RHSA-2022:4717
RHSA-2022:4721
RHSA-2022:5157
RHSA-2022_0819
RHSA-2022_0825
RHSA-2022_1417
RHSA-2022_4642
RHSA-2022_4644
RLSA-2022:0819
RLSA-2022:0825
RLSA-2022_0819
RLSA-2022_0825
SUSE-SU-2022:0755-1
SUSE-SU-2022:0756-1
SUSE-SU-2022:0757-1
SUSE-SU-2022:0759-1
SUSE-SU-2022:0760-1
SUSE-SU-2022:0761-1
SUSE-SU-2022:0762-1
SUSE-SU-2022:0765-1
SUSE-SU-2022:0766-1
SUSE-SU-2022:0767-1
SUSE-SU-2022:0768-1
SUSE-SU-2022:0978-1
SUSE-SU-2022:0984-1
SUSE-SU-2022:0991-1
SUSE-SU-2022:0998-1
SUSE-SU-2022:1012-1
SUSE-SU-2022:1035-1
SUSE-SU-2022:1036-1
SUSE-SU-2022:1038-1
SUSE-SU-2022:1257-1
SUSE-SU-2022:14905-1
SUSE-SU-2022_0756-1
SUSE-SU-2022_0762-1
SUSE-SU-2022_0765-1
SUSE-SU-2022_0766-1
SUSE-SU-2022_0767-1
SUSE-SU-2022_0768-1
SUSE-SU-2022_0991-1
SUSE-SU-2022_1012-1
SUSE-SU-2022_1035-1
SUSE-SU-2022_1036-1
SUSE-SU-2022_14905-1
USN-5302-1
USN-5337-1
USN-5338-1
USN-5339-1
USN-5343-1
USN-5362-1
USN-5368-1
USN-5377-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu