CVE-2022-0492

Hoch7.8Veröffentlicht am 3. März 2022

Eine Schwachstelle wurde in cgroup_release_agent_write des Linux kernel in der Funktion kernel/cgroup/cgroup-v1.c gefunden. Dieser Fehler ermöglicht es unter bestimmten Umständen, das cgroups v1 release_agent-Feature zu nutzen, um unerwartet Privilegien zu eskalieren und die namespace isolation zu umgehen.

Aktiv ausgenutzt

  • Seit dem 2. Juni 2026 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 5. Juni 2026 beheben (BOD 22-01)
  • Erster Angriff 1550 Tage nach der Veröffentlichung beobachtet

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Quelle: CISA KEV · 10. Juli 2026 2. Juni 2026 2. Juni 2026 1. Juni 2026

CVSS-Score7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-287, CWE-862
Herstellerredhat, debian, netapp, linux

Betroffene Produkte

HerstellerProduktVersionen
netapph300s firmware-
netapph300s-
netapph410c firmware-
netapph410c-
netapph410s firmware-
netapph410s-
netapph500s firmware-
netapph500s-
netapph700s firmware-
netapph700s-
netappbootstrap os-
netapphci compute node-
linuxlinux kernel< 4.9.301
debiandebian linux9.0
redhatcodeready linux builder8.0
redhatcodeready linux builder for power little endian8.0
redhatvirtualization host4.0
redhatenterprise linux8.0
redhatenterprise linux eus8.2
redhatenterprise linux for ibm z systems8.0
redhatenterprise linux for ibm z systems eus8.0
redhatenterprise linux for power little endian8.0
redhatenterprise linux for power little endian eus8.0
redhatenterprise linux for real time for nfv tus8.0
redhatenterprise linux for real time tus8.0

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.

CVE-Datenbank