CISA Flags Actively Exploited Linux Kernel Vulnerability
Want more insights like this?
CISA added CVE-2022-0492 to its Known Exploited Vulnerabilities catalog on 2 June after confirming active exploitation in the wild — a four-year-old Linux kernel privilege escalation flaw, public for roughly three years, that attackers have only now started using. Kaspersky reported the exploitation a day before CISA's alert, without naming the attackers or victims.
The flaw (CVSS 7.8) targets the cgroups v1 release_agent feature, allowing attackers to execute arbitrary commands with root-level access — and potentially break out of containerized environments entirely. It's especially dangerous in cloud-native setups where containers rely on cgroups for resource isolation.
The federal remediation deadline was 5 June. Everyone else should move fast too: update the kernel, disable unprivileged user namespaces where you can, and audit container configurations for suspicious cgroup activity.
Source: Cybersecurity News