Vulnerability Intelligence Report
Linux Kernel Improper Authentication Vulnerability
CVE-2022-0492
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:5.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗CWE-287
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| netapp | h300s_firmware | all |
| netapp | h300s | all |
| netapp | h410c_firmware | all |
| netapp | h410c | all |
| netapp | h410s_firmware | all |
| netapp | h410s | all |
| netapp | h500s_firmware | all |
| netapp | h500s | all |
| netapp | h700s_firmware | all |
| netapp | h700s | all |
| netapp | bootstrap_os | all |
| netapp | hci_compute_node | all |
| linux | linux_kernel | 5.17 |
| debian | debian_linux | 9.0, 10.0, 11.0 |
| redhat | codeready_linux_builder | 8.0, 8.2 |
| redhat | codeready_linux_builder_for_power_little_endian | 8.0, 8.2 |
| redhat | virtualization_host | 4.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.2 |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.0 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.0 |
| redhat | enterprise_linux_for_real_time_for_nfv_tus | 8.0, 8.2 |
| redhat | enterprise_linux_for_real_time_tus | 8.0, 8.2 |
| redhat | enterprise_linux_server_aus | 8.2 |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.1, 8.2 |
| redhat | enterprise_linux_server_tus | 8.2 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.1, 8.2 |
| canonical | ubuntu_linux | 14.04, 16.04, 18.04, 20.04, 22.04 |
| fedoraproject | fedora | 35 |
| netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | all |
| netapp | solidfire_\&_hci_management_node | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
EPSS Score
5.528%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2022-02-04T00:00:00 |
| Published | 2022-03-03T00:00:00 |
| Last Updated | 2026-06-03T03:55:20 |
Community Chatter & Buzz