CVE-2022-0492
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Linux Kernel Improper Authentication Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 6% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-287, CWE-862
מוצרים מושפעים
netapp: h300s firmware; netapp: h300s; netapp: h410c firmware; netapp: h410c; netapp: h410s firmware; netapp: h410s; netapp: h500s firmware; netapp: h500s; netapp: h700s firmware; netapp: h700s; netapp: bootstrap os; netapp: hci compute node; linux: linux kernel; debian: debian linux; redhat: codeready linux builder
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… PatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… PatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2051505 Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2051505 Issue TrackingPatchThird Party Advisory
- http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html ExploitVDB Entry
- http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html ExploitVDB Entry
- http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-… Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html Mailing ListThird Party Advisory