CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks
ID: c12f3f79-d4e8-5302-8887-1f90daae8733
STIX ID: report--c12f3f79-d4e8-5302-8887-1f90daae8733
Feed Name: cybersecurityNews.com
CVE-2022-0492 is an improper authentication flaw in the Linux kernel's cgroups v1 release_agent functionality that can allow a local attacker or a compromised container to execute arbitrary commands with elevated (root) privileges on the host. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog citing active exploitation, and federal agencies are required to remediate by June 5, 2026; mitigations include patching the kernel, disabling unprivileged user namespaces, and restricting cgroup access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
