Junglewise Threat Intelligence

CVE-2022-0492: Linux Kernel privilege escalation in cgroups v1 release_agent

CVE-2022-0492 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-06-02

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability in the Linux Kernel could allow a user with limited access to gain full administrative control over a system. This issue specifically affects how the system manages 'containers' (isolated environments used to run applications), potentially allowing an attacker to break out of a restricted environment and access sensitive data or disrupt operations on the host machine. This vulnerability has been reported as being exploited in the wild.

Technical details

A vulnerability exists in the Linux kernel's cgroup_release_agent_write function within kernel/cgroup/cgroup-v1.c. The flaw stems from missing authorization checks when configuring the release_agent feature in cgroups v1. A local attacker with low privileges can exploit this to execute arbitrary code with root privileges or bypass namespace isolation to escape a container. The vulnerability is reachable if an attacker can mount a cgroupfs or modify the release_agent file. Patches have been released in the mainline kernel and various long-term support distributions.

Affected products

  • Linux Linux Kernel 2.6.24 to 5.17-rc2

Timeline

  • 2022-03-07: advisory: Initial disclosure and Debian security advisories published
  • 2022-04-19: advisory: NetApp advisory published
  • 2026-06-02: disclosed: CISA-ADP enrichment and updated publication date