CVE-2022-0492
È stata trovata una vulnerabilità in cgroup_release_agent_write del kernel Linux nella funzione kernel/cgroup/cgroup-v1.c. Questa falla, in determinate circostanze, consente l'uso della funzionalità release_agent di cgroups v1 per escalare i privilegi e bypassare inaspettatamente l'isolamento dei namespace.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 2 giu 2026
- Le agenzie federali statunitensi devono correggerla entro il 5 giu 2026 (direttiva BOD 22-01)
- Primo attacco osservato 1550 giorni dopo la divulgazione
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Fonte: CISA KEV · 10 lug 2026 2 giu 2026 2 giu 2026 1 giu 2026
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HProdotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| netapp | h300s firmware | - |
| netapp | h300s | - |
| netapp | h410c firmware | - |
| netapp | h410c | - |
| netapp | h410s firmware | - |
| netapp | h410s | - |
| netapp | h500s firmware | - |
| netapp | h500s | - |
| netapp | h700s firmware | - |
| netapp | h700s | - |
| netapp | bootstrap os | - |
| netapp | hci compute node | - |
| linux | linux kernel | < 4.9.301 |
| debian | debian linux | 9.0 |
| redhat | codeready linux builder | 8.0 |
| redhat | codeready linux builder for power little endian | 8.0 |
| redhat | virtualization host | 4.0 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux eus | 8.2 |
| redhat | enterprise linux for ibm z systems | 8.0 |
| redhat | enterprise linux for ibm z systems eus | 8.0 |
| redhat | enterprise linux for power little endian | 8.0 |
| redhat | enterprise linux for power little endian eus | 8.0 |
| redhat | enterprise linux for real time for nfv tus | 8.0 |
| redhat | enterprise linux for real time tus | 8.0 |
Articoli correlati
VulnerabilitàFortinet corregge falle critiche in FortiWeb e FortiManager
Fortinet ha pubblicato aggiornamenti di sicurezza per otto vulnerabilità distribuite tra FortiWeb, FortiManager, FortiClientWindows, FortiOS e FortiSIEM.
APTSPECTRE, la backdoor che spegne gli EDR: dentro l’arsenale di UAT-10147
Analisi della backdoor SPECTRE utilizzata dal gruppo UAT-10147 per disattivare gli EDR, con dettagli su catene di attacco e uso di AI.
AIAgenti AI fuori controllo: sfruttate due vulnerabilità, CISA le inserisce nel KEV con scadenze immediate
Gli agenti AI di OpenAI hanno sfruttato vulnerabilità zero-day in Linux e JFrog. CISA le aggiunge al KEV con scadenze immediate: aggiorna i sistemi ora.
This product uses the NVD API but is not endorsed or certified by the NVD.
La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.