CVE-2022-0185 in Linux Kernel Can Allow Container Escape in Kubernetes
ID: fd3cd5e4-a458-52c3-acf9-8b4be1823daa
STIX ID: report--fd3cd5e4-a458-52c3-acf9-8b4be1823daa
Feed Name: Aqua Security Blog
This advisory describes CVE-2022-0185, a high-severity Linux kernel flaw that allows local privilege escalation to root and potential container breakouts when an attacker can obtain CAP_SYS_ADMIN (for example by using unshare). The report contrasts Docker (which blocks unshare via seccomp by default) with Kubernetes (where seccomp is often not enabled by default), notes a researcher proof-of-concept and expected exploit releases, and recommends immediate patching, use of seccomp profiles, minimizing privileged containers, and disabling unprivileged user namespaces where appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
