Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0492

79
FAUCET Score

CVE-2022-0492 is a high-severity privilege escalation vulnerability in the Linux kernel's cgroups v1 release_agent feature, affecting various Linux distributions including Canonical, Debian, Fedora, and Red Hat. With a CVSS score of 7.8, it allows a local attacker to bypass namespace isolation and gain elevated privileges, leading to high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, a Metasploit module exists for container escape, and the vulnerability has garnered significant community attention and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
5.53%
Probability of exploitation in next 30 days
EPSS Percentile
92.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jun 2, 2026
Metasploit: Docker cgroups Container Escape · Feb 4, 2022
This CVE's current EPSS score of 0.0553 is in the 98th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (32)

boschpatch availablevia llm_extracted
Fixed in: 1.19.16-gke.7800 or later
View patch
microsoftpatch availablevia msrc
Product: 18765-16823Fixed in: 5.15.26.1-2
microsoftpatch availablevia msrc
Product: 18768-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 kernel 5.10.102.1-3 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.26.1-2 on CBL Mariner 2.0Fixed in: 5.15.26.1-2
mongodbpatch availablevia llm_extracted
Fixed in: 1.19.16-gke.7800 or later
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: kernel-0:3.10.0-514.101.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: kernel-0:3.10.0-693.103.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)Fixed in: kernel-0:3.10.0-957.94.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Telco Extended Update SupportFixed in: kernel-0:3.10.0-957.94.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-957.94.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Advanced Update SupportFixed in: kernel-0:3.10.0-1062.67.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Telco Extended Update SupportFixed in: kernel-0:3.10.0-1062.67.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-1062.67.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-348.20.1.rt7.150.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-348.20.1.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-147.64.1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kernel-rt-0:4.18.0-193.79.1.rt13.129.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kernel-0:4.18.0-193.79.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-rt-0:4.18.0-305.45.1.rt7.117.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-0:4.18.0-305.45.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle SupportFixed in: kernel-0:2.6.32-754.47.1.el6
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-1160.66.1.rt56.1207.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-1160.66.1.el7
View patch

Vendor Advisories (4)

boschllm-bosch-770314eba9a3f2e8LOW

Linux kernel cgroup_release_agent_write vulnerability (CVE-2022-0492)

May 12, 2022
mongodbllm-mongodb-e0c418cab95015d9LOW

Linux kernel cgroup_release_agent_write vulnerability (CVE-2022-0492)

May 12, 2022
microsoft2022-Mar/CVE-2022-0492Important

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw under certain circumstances allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

Mar 8, 2022
redhatCVE-2022-0492Important

kernel: cgroups v1 release_agent feature may allow privilege escalation

Feb 7, 2022

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/176099/Docker-cgroups-Container-Escape.html
ExploitVDB Entry
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
PatchVendor Advisory
lists.debian.org / debian-lts-announce/2022/03/msg00011.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2022/03/msg00012.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20220419-0002
Third Party Advisory
debian.org / security/2022/dsa-5095
Third Party Advisory
debian.org / security/2022/dsa-5096
Third Party Advisory