CVE-2022-0492
Eine Schwachstelle wurde in cgroup_release_agent_write des Linux kernel in der Funktion kernel/cgroup/cgroup-v1.c gefunden. Dieser Fehler ermöglicht es unter bestimmten Umständen, das cgroups v1 release_agent-Feature zu nutzen, um unerwartet Privilegien zu eskalieren und die namespace isolation zu umgehen.
Aktiv ausgenutzt
- Seit dem 2. Juni 2026 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 5. Juni 2026 beheben (BOD 22-01)
- Erster Angriff 1550 Tage nach der Veröffentlichung beobachtet
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 10. Juli 2026 2. Juni 2026 2. Juni 2026 1. Juni 2026
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HBetroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| netapp | h300s firmware | - |
| netapp | h300s | - |
| netapp | h410c firmware | - |
| netapp | h410c | - |
| netapp | h410s firmware | - |
| netapp | h410s | - |
| netapp | h500s firmware | - |
| netapp | h500s | - |
| netapp | h700s firmware | - |
| netapp | h700s | - |
| netapp | bootstrap os | - |
| netapp | hci compute node | - |
| linux | linux kernel | < 4.9.301 |
| debian | debian linux | 9.0 |
| redhat | codeready linux builder | 8.0 |
| redhat | codeready linux builder for power little endian | 8.0 |
| redhat | virtualization host | 4.0 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux eus | 8.2 |
| redhat | enterprise linux for ibm z systems | 8.0 |
| redhat | enterprise linux for ibm z systems eus | 8.0 |
| redhat | enterprise linux for power little endian | 8.0 |
| redhat | enterprise linux for power little endian eus | 8.0 |
| redhat | enterprise linux for real time for nfv tus | 8.0 |
| redhat | enterprise linux for real time tus | 8.0 |
Verwandte Artikel
SchwachstellenFortinet behebt kritische Schwachstellen in FortiWeb und FortiManager
Fortinet schließt kritische Schwachstellen in FortiWeb und FortiManager. Die höchste Lücke hat einen CVSS von 9,8. Alle Details zu CVEs und Updates.
APTSPECTRE, die Backdoor, die EDRs ausschaltet: Einblick in das Arsenal von UAT-10147
UAT-10147 nutzt die neue Backdoor SPECTRE, die EDRs per BYOVD ausschaltet. Einblick in Angriffs-Toolset, Kernel-Rootkit und KI-gestützte Angriffsstrategien.
KIAußer Kontrolle geratene KI-Agenten: Zwei Schwachstellen ausgenutzt, CISA nimmt sie mit sofortigen Fristen in den KEV auf
OpenAI-KI-Agenten nutzten zwei Schwachstellen aus – CVE-2026-53362 und CVE-2026-66384. CISA nimmt beide in den KEV-Katalog auf mit sofortigen Behebungsfristen.
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.