CVE-2022-0492

high KEV EU-EXPLOITED
EUVD alias: EUVD-2022-15629
Published 2022-03-10 ยท Modified 2026-06-02
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

CISA KEV

Vendor
Linux
Product
Kernel
Due date
2026-06-05

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Metasploit modules

Docker cgroups Container Escape
Source fetch failed: fetch_error โ€” view the original via the link above.

OS impact

fedora Fedora Affected 1 release
VersionStatusFixed in
35 Affected โ€”
linux Linux kernel Affected 2 releases
VersionStatusFixed in
5.17 Affected โ€”
โ€” Affected 4.9.301
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
ubuntu Ubuntu Affected 5 releases
VersionStatusFixed in
22.04 Affected โ€”
20.04 Affected โ€”
18.04 Affected โ€”
16.04 Affected โ€”
14.04 Affected โ€”
debian Debian Mixed 8 releases
VersionStatusFixed in
trixie Fixed 5.16.7-1
sid Fixed 5.16.7-1
forky Fixed 5.16.7-1
bullseye Fixed 5.10.103-1
bookworm Fixed 5.16.7-1
11.0 Affected โ€”
10.0 Affected โ€”
9.0 Affected โ€”
redhat Red Hat Mixed 3 releases
VersionStatusFixed in
8.2 Affected โ€”
8.0 Affected โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Application impact

VendorProductVersionsFixed
redhat redhatcodeready_linux_builder8.0
redhat redhatcodeready_linux_builder8.2
redhat redhatcodeready_linux_builder_for_power_little_endian8.0
redhat redhatcodeready_linux_builder_for_power_little_endian8.2
redhat redhatvirtualization_host4.0
netappsolidfire\,_enterprise_sds_\&_hci_storage_node-
netappsolidfire_\&_hci_management_node-
netapph300e-
netapph300s-
netapph410c-
netapph410s-
netapph500e-
netapph500s-
netapph700e-
netapph700s-
netapphci_compute_node-

References

CWEs

CWE-287 CWE-862

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.