Executive brief
A security vulnerability in the Linux Kernel could allow a user with limited access to gain full administrative control over a system. This issue specifically affects how the system manages 'containers' (isolated environments used to run applications), potentially allowing an attacker to break out of a restricted environment and access sensitive data or disrupt operations on the host machine. This vulnerability has been reported as being exploited in the wild.
Technical details
A vulnerability exists in the Linux kernel's cgroup_release_agent_write function within kernel/cgroup/cgroup-v1.c. The flaw stems from missing authorization checks when configuring the release_agent feature in cgroups v1. A local attacker with low privileges can exploit this to execute arbitrary code with root privileges or bypass namespace isolation to escape a container. The vulnerability is reachable if an attacker can mount a cgroupfs or modify the release_agent file. Patches have been released in the mainline kernel and various long-term support distributions.
Affected products
- Linux Linux Kernel 2.6.24 to 5.17-rc2
Timeline
- 2022-03-07: advisory: Initial disclosure and Debian security advisories published
- 2022-04-19: advisory: NetApp advisory published
- 2026-06-02: disclosed: CISA-ADP enrichment and updated publication date