CVE-2022-0492

Alta7.8Pubblicata il 3 marzo 2022

È stata trovata una vulnerabilità in cgroup_release_agent_write del kernel Linux nella funzione kernel/cgroup/cgroup-v1.c. Questa falla, in determinate circostanze, consente l'uso della funzionalità release_agent di cgroups v1 per escalare i privilegi e bypassare inaspettatamente l'isolamento dei namespace.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 2 giu 2026
  • Le agenzie federali statunitensi devono correggerla entro il 5 giu 2026 (direttiva BOD 22-01)
  • Primo attacco osservato 1550 giorni dopo la divulgazione

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Fonte: CISA KEV · 10 lug 2026 2 giu 2026 2 giu 2026 1 giu 2026

Punteggio CVSS7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-287, CWE-862
Vendorredhat, debian, netapp, linux

Prodotti coinvolti

VendorProdottoVersioni
netapph300s firmware-
netapph300s-
netapph410c firmware-
netapph410c-
netapph410s firmware-
netapph410s-
netapph500s firmware-
netapph500s-
netapph700s firmware-
netapph700s-
netappbootstrap os-
netapphci compute node-
linuxlinux kernel< 4.9.301
debiandebian linux9.0
redhatcodeready linux builder8.0
redhatcodeready linux builder for power little endian8.0
redhatvirtualization host4.0
redhatenterprise linux8.0
redhatenterprise linux eus8.2
redhatenterprise linux for ibm z systems8.0
redhatenterprise linux for ibm z systems eus8.0
redhatenterprise linux for power little endian8.0
redhatenterprise linux for power little endian eus8.0
redhatenterprise linux for real time for nfv tus8.0
redhatenterprise linux for real time tus8.0

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.

Database CVE