IM
IronMonkey Threat Research

CVE-2022-0492 HIGH

Published: 2022-03-03 | Last Modified: 2026-06-03 | Status: Analyzed

Description

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

Additional Descriptions (1)

Se ha encontrado una vulnerabilidad en la función cgroup_release_agent_write en el archivo kernel/cgroup/cgroup-v1.c del kernel de Linux. Este fallo, bajo determinadas circunstancias, permite el uso de la función cgroups v1 release_agent para escalar privilegios y saltarse el aislamiento del espacio de nombres de forma no esperada

CVSS Metrics

Base Score: 7.8 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 5.9

Base Score: 6.9 (MEDIUM)

AV:L/AC:M/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.4

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-287
[email protected] Primary
en CWE-862

Affected Products

Vendor Product Version Update Type
netapp h300s_firmware - <built-in method update of dict object at 0x72a9cd07a2c0> Operating System
netapp h410c_firmware - <built-in method update of dict object at 0x72a9cc46d740> Operating System
netapp h410s_firmware - <built-in method update of dict object at 0x72a9b0c9ab80> Operating System
netapp h500s_firmware - <built-in method update of dict object at 0x72a9b0c3e600> Operating System
netapp h700s_firmware - <built-in method update of dict object at 0x72a9cd07b0c0> Operating System
netapp bootstrap_os - <built-in method update of dict object at 0x72a9cd07bb40> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9b0c9b540> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9b0c9bcc0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9cc46d380> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9cd07ba00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9e526eec0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9cd0c0180> Operating System
linux linux_kernel * <built-in method update of dict object at 0x72a9b0c9a300> Operating System
linux linux_kernel 5.17 <built-in method update of dict object at 0x72a9cc7ed900> Operating System
linux linux_kernel 5.17 <built-in method update of dict object at 0x72a9b0734140> Operating System
debian debian_linux 9.0 <built-in method update of dict object at 0x72a9b0c9a540> Operating System
debian debian_linux 10.0 <built-in method update of dict object at 0x72a9cd0791c0> Operating System
debian debian_linux 11.0 <built-in method update of dict object at 0x72a9b0c99b40> Operating System
redhat codeready_linux_builder 8.0 <built-in method update of dict object at 0x72a9cc46f480> Application
redhat codeready_linux_builder 8.2 <built-in method update of dict object at 0x72a9cc60e780> Application
redhat codeready_linux_builder_for_power_little_endian 8.0 <built-in method update of dict object at 0x72a9cd0c3f80> Application
redhat codeready_linux_builder_for_power_little_endian 8.2 <built-in method update of dict object at 0x72a9b0c9b880> Application
redhat virtualization_host 4.0 <built-in method update of dict object at 0x72a9b0c99500> Application
redhat enterprise_linux 8.0 <built-in method update of dict object at 0x72a9cd0c3540> Operating System
redhat enterprise_linux_eus 8.2 <built-in method update of dict object at 0x72a9b0b027c0> Operating System
redhat enterprise_linux_for_ibm_z_systems 8.0 <built-in method update of dict object at 0x72a9b0734f80> Operating System
redhat enterprise_linux_for_ibm_z_systems_eus 8.0 <built-in method update of dict object at 0x72a9cd07be40> Operating System
redhat enterprise_linux_for_power_little_endian 8.0 <built-in method update of dict object at 0x72a9cd0c3b00> Operating System
redhat enterprise_linux_for_power_little_endian_eus 8.0 <built-in method update of dict object at 0x72a9cc6475c0> Operating System
redhat enterprise_linux_for_real_time_for_nfv_tus 8.0 <built-in method update of dict object at 0x72a9cc647580> Operating System
redhat enterprise_linux_for_real_time_for_nfv_tus 8.2 <built-in method update of dict object at 0x72a9cc7ee640> Operating System
redhat enterprise_linux_for_real_time_tus 8.0 <built-in method update of dict object at 0x72a9cc646e80> Operating System
redhat enterprise_linux_for_real_time_tus 8.2 <built-in method update of dict object at 0x72a9cc6461c0> Operating System
redhat enterprise_linux_server_aus 8.2 <built-in method update of dict object at 0x72a9cc644bc0> Operating System
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.1 <built-in method update of dict object at 0x72a9cc645080> Operating System
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.2 <built-in method update of dict object at 0x72a9cc647180> Operating System
redhat enterprise_linux_server_tus 8.2 <built-in method update of dict object at 0x72a9cc6462c0> Operating System
redhat enterprise_linux_server_update_services_for_sap_solutions 8.1 <built-in method update of dict object at 0x72a9cc645000> Operating System
redhat enterprise_linux_server_update_services_for_sap_solutions 8.2 <built-in method update of dict object at 0x72a9cc646cc0> Operating System
canonical ubuntu_linux 14.04 <built-in method update of dict object at 0x72a9cc646dc0> Operating System
canonical ubuntu_linux 16.04 <built-in method update of dict object at 0x72a9cc7edd40> Operating System
canonical ubuntu_linux 18.04 <built-in method update of dict object at 0x72a9cc7ee440> Operating System
canonical ubuntu_linux 20.04 <built-in method update of dict object at 0x72a9cc7efac0> Operating System
canonical ubuntu_linux 22.04 <built-in method update of dict object at 0x72a9cc7ecac0> Operating System
fedoraproject fedora 35 <built-in method update of dict object at 0x72a9cc647400> Operating System
netapp solidfire\,_enterprise_sds_\&_hci_storage_node - <built-in method update of dict object at 0x72a9cc6470c0> Application
netapp solidfire_\&_hci_management_node - <built-in method update of dict object at 0x72a9cc646640> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:redhat:codeready_linux_builder:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:solidfire\,_enterprise_sds_\&_hci_storage_node:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

References

Notification
Message here