logo

CVE-2022-0185 in Linux Kernel Can Allow Container Escape in Kubernetes

ID: fd3cd5e4-a458-52c3-acf9-8b4be1823daa

STIX ID: report--fd3cd5e4-a458-52c3-acf9-8b4be1823daa

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-01-24

Date Updated: 2026-04-26

...
...

This advisory describes CVE-2022-0185, a high-severity Linux kernel flaw that allows local privilege escalation to root and potential container breakouts when an attacker can obtain CAP_SYS_ADMIN (for example by using unshare). The report contrasts Docker (which blocks unshare via seccomp by default) with Kubernetes (where seccomp is often not enabled by default), notes a researcher proof-of-concept and expected exploit releases, and recommends immediate patching, use of seccomp profiles, minimizing privileged containers, and disabling unprivileged user namespaces where appropriate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.