CVE-2022-0492
CVE-2022-0492
In short
A flaw in the Linux kernel's cgroup feature allows an attacker to bypass security boundaries (namespace isolation) and gain elevated privileges. This happens when using cgroups v1 release_agent, which is a Linux system feature that normally should be restricted.
Technical detail
CVE-2022-0492 is a privilege escalation vulnerability in kernel/cgroup/cgroup-v1.c affecting cgroups v1 release_agent functionality. An unprivileged user can exploit improper isolation enforcement to escape namespace boundaries and obtain elevated privileges, bypassing intended access controls under specific system configurations.
Summary generated and translated by AI from the official description.
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · kernelpublic PoCs found — 11
githubgithub.com/PaloAltoNetworks/can-ctr-escape-cve-2022-0492★ 47githubgithub.com/chenaotian/CVE-2022-0492★ 32githubgithub.com/SofianeHamlaoui/CVE-2022-0492-Checker★ 11githubgithub.com/T1erno/CVE-2022-0492-Docker-Breakout-Checker-and-PoC★ 6githubgithub.com/KianaBin/CVE-2022-0492-Container-Escape★ 2githubgithub.com/smallcat9612/CVE-2022-0492-Docker-Breakout-Checker-and-PoC★ 0githubgithub.com/Trinadh465/device_renesas_kernel_AOSP10_r33_CVE-2022-0492★ 0githubgithub.com/Perimora/cve_2022_0492★ 0cve_referencepacketstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlunverifiedcve_referencepacketstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.htmlunverifiedcve_referencepacketstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.htmlhttp://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlhttp://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2051505https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02afhttps://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20220419-0002/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0492https://www.debian.org/security/2022/dsa-5095https://www.debian.org/security/2022/dsa-5096