Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

CVE-2022-0492: Privilege escalation vulnerability causing container escape

Blog post from Sysdig

Post Details
Company
Date Published
Author
Stefano Chierici
Word Count
1,518
Language
English
Hacker News Points
-
Summary

CVE-2022-0492 is a high-severity (7.0) privilege escalation vulnerability in the Linux Kernel's cgroup_release_agent_write function, allowing attackers to escape container environments and gain root privileges. Found in cgroups v1, this vulnerability is exploitable by attackers with root access when containers run without security practices like SELinux, AppArmor, or Seccomp enabled. Although a patch is available in kernel version 5.17 rc3, the ease of exploitation necessitates proactive security measures such as using runtime detection tools like Falco and enforcing admission policies with tools like OPA. These measures help prevent exploitation by ensuring container environments are secure and up to date.