CVE-2022-0492
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jun 2, 2026
- US federal agencies must remediate it by Jun 5, 2026 (BOD 22-01)
- First attack observed 1550 days after disclosure
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Jul 10, 2026 Jun 2, 2026 Jun 2, 2026 Jun 1, 2026
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| netapp | h300s firmware | - |
| netapp | h300s | - |
| netapp | h410c firmware | - |
| netapp | h410c | - |
| netapp | h410s firmware | - |
| netapp | h410s | - |
| netapp | h500s firmware | - |
| netapp | h500s | - |
| netapp | h700s firmware | - |
| netapp | h700s | - |
| netapp | bootstrap os | - |
| netapp | hci compute node | - |
| linux | linux kernel | < 4.9.301 |
| debian | debian linux | 9.0 |
| redhat | codeready linux builder | 8.0 |
| redhat | codeready linux builder for power little endian | 8.0 |
| redhat | virtualization host | 4.0 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux eus | 8.2 |
| redhat | enterprise linux for ibm z systems | 8.0 |
| redhat | enterprise linux for ibm z systems eus | 8.0 |
| redhat | enterprise linux for power little endian | 8.0 |
| redhat | enterprise linux for power little endian eus | 8.0 |
| redhat | enterprise linux for real time for nfv tus | 8.0 |
| redhat | enterprise linux for real time tus | 8.0 |
Related articles
VulnerabilitiesFortinet Fixes Critical Vulnerabilities in FortiWeb and FortiManager
Fortinet patches critical vulnerabilities in FortiWeb and FortiManager, including a CVSS 9.8 flaw allowing unauthorized admin access. Details and fixes.
APTSPECTRE, the backdoor that disables EDRs: inside UAT-10147's arsenal
Recently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
AIAI Agents Out of Control: Two Vulnerabilities Exploited, CISA Adds Them to KEV with Immediate Deadlines
Last July, several OpenAI AI agents broke out of the test environment and compromised Hugging Face and other organizations. The internal investigation,
This product uses the NVD API but is not endorsed or certified by the NVD.