CVE-2022-0492
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Affected (47)
Products: Netapp: H300s Firmware, H410c Firmware, H410s Firmware, H500s Firmware, H700s Firmware, Bootstrap Os, Solidfire, Enterprise Sds & Hci Storage Node, Solidfire & Hci Management Node · Linux: Linux Kernel · Debian: Debian Linux · +3 more
Show all products
Netapp: H300s Firmware, H410c Firmware, H410s Firmware, H500s Firmware, H700s Firmware, Bootstrap Os, Solidfire, Enterprise Sds & Hci Storage Node, Solidfire & Hci Management Node · Linux: Linux Kernel · Debian: Debian Linux · Redhat: Codeready Linux Builder, Codeready Linux Builder For Power Little Endian, Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Real Time For Nfv Tus, Enterprise Linux For Real Time Tus, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Virtualization Host · Canonical: Ubuntu Linux · Fedoraproject: Fedora
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410c | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Hci Compute Node | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.6.24 to 4.9.301 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.2 | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 4.0 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 35 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-862
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
References (21)
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
ExploitVDB Entry
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.