Skip to content

kernel CVE-2022-0492

High
arnaldo2792 published GHSA-cc3r-wh87-c924 Feb 8, 2022

Package

kernel (bottlerocket)

Affected versions

< 1.6.0

Patched versions

1.6.0

Description

It has been discovered that under certain circumstances, the Linux kernel’s cgroups v1 release_agent feature can be used to escalate privilege and bypass namespace isolation unexpectedly.

This is corrected by requiring CAP_SYS_ADMIN in the initial user namespace when setting release_agent.

Severity

High

CVE ID

CVE-2022-0492

Weaknesses

No CWEs