CISA Warns of Exploited Linux Kernel Vulnerability CVE-2022-0492
TL;DR. CISA issued a warning about active exploitation of CVE-2022-0492, a Linux kernel vulnerability enabling container escapes and privilege escalation. - The flaw affects cgroups v1, allowing attackers to elevate privileges and bypass namespace isolation. - Exploitation involves modifying a release_agent file to run malicious scripts as root within containers. - Kaspersky reported in-the-wild attacks leveraging this vulnerability targeting container environments.
- CISA has added CVE-2022-0492 to its Known Exploited Vulnerabilities catalog.
- The vulnerability allows for privilege escalation and container escape in Linux environments.
- Attackers can leverage the cgroups v1 flaw to execute malicious code with root privileges.
Sources
- Organizations Warned of Exploited Linux Kernel Vulnerability — securityweek.com
- bleepingcomputer.com — bleepingcomputer.com