CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability
A vulnerability was found in cgroupreleaseagentwrite in kernel/cgroup/cgroup-v1.c in the Linux kernel. In this flaw, under certain circumstances, the cgroups v1 releaseagent feature can be used to escalate privilege and bypass namespace isolation unexpectedly.
Upstream Commit:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af
Other sources
A vulnerability was found in the Linux kernel’s cgroupreleaseagentwrite in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 releaseagent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 releaseagent feature.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:2.6.32-754.47.1.el6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.66.1.rt56.1207.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.66.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.101.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.103.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.94.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.67.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-348.20.1.rt7.150.el8_5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-348.20.1.el8_5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.64.1.el8_1 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.79.1.rt13.129.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.79.1.el8_2 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.45.1.rt7.117.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.45.1.el8_4 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.17 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.135-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.27-1 - Remove
Remove
debian/linuxfrom your environment.Discontinue use of this product if vendor mitigations are unavailable or cannot be applied.
- Remove
Remove
redhat/kernelfrom your environment.Discontinue use of this product if vendor mitigations are unavailable or cannot be applied.
- Remove
Remove
redhat/kernel-rtfrom your environment.Discontinue use of this product if vendor mitigations are unavailable or cannot be applied.
- Compensating control
Apply vendor-provided mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services; restrict or isolate vulnerable systems until fixes are applied.
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:1417
- RHSA-2022:4644
- RHSA-2022:4642
- RHSA-2022:4655
- RHSA-2022:2189
- RHSA-2022:5157
- RHSA-2022:2186
- RHSA-2022:2211
- RHSA-2022:4717
- RHSA-2022:4721
- RHSA-2022:0819
- RHSA-2022:0825
- RHSA-2022:0849
- RHSA-2022:0823
- RHSA-2022:0851
- RHSA-2022:0958
- RHSA-2022:0821
- RHSA-2022:0820
- RHSA-2022:0925
- RHSA-2022:1413
- RHSA-2022:1418
- RHSA-2022:1455
Frequently Asked Questions
What is the severity of CVE-2022-0492?
CVE-2022-0492 has a high severity rating due to its potential to escalate privileges and bypass namespace isolation.
How do I fix CVE-2022-0492?
To fix CVE-2022-0492, update to the latest version of the Linux kernel as specified in Red Hat's errata.
Which versions of the Linux kernel are affected by CVE-2022-0492?
CVE-2022-0492 affects various versions of the Linux kernel, including 2.6.32 and all versions up to 5.17.
Is CVE-2022-0492 a remote exploit?
CVE-2022-0492 is not classified as a remote exploit; it requires local access to exploit the vulnerability.
What types of systems are vulnerable to CVE-2022-0492?
CVE-2022-0492 affects systems running affected versions of the Linux kernel, including various distributions like Red Hat and Debian.