logo

Linux Kernel Vulnerability: Escaping Containers by Abusing Cgroups

ID: 139ea1e3-4f0a-5f5b-afe9-b20d8ea3d9c3

STIX ID: report--139ea1e3-4f0a-5f5b-afe9-b20d8ea3d9c3

Feed Name: Aqua Security Blog

Threat Score
60/100

Date Published: 2022-03-09

Date Updated: 2026-04-26

...
...

**Executive summary:** CVE-2022-0492 is a high-severity Linux kernel vulnerability in cgroups' release_agent that can permit container escape under specific conditions; while Docker's default seccomp and AppArmor usually mitigate exploitation, Kubernetes disables seccomp by default and user namespaces increase risk, so the report urges prompt patching, reboots, enabling container defenses (seccomp/AppArmor), avoiding running containers as root, and disabling unused user namespaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.