A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
CVE-2022-0492
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2026-06-02), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 7.8
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS
- 92.0%
- KEV
- ⚠ Exploited
Published
March 3, 2022
Last Modified
June 3, 2026
Advisory Details (10)
Auto-updated Jun 3, 2026Packet Storm
http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.htmlPacket Storm
http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html[SECURITY] [DSA 5096-1] linux security update
https://www.debian.org/security/2022/dsa-5096[SECURITY] [DLA 2941-1] linux-4.19 security update
https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html[SECURITY] [DLA 2940-1] linux security update
https://lists.debian.org/debian-lts-announce/2022/03/msg00011.htmlcgroup-v1: Require capabilities to set release_agent - kernel/git/torvalds/linux.git - Linux kernel source tree
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af2051505 – (CVE-2022-0492) CVE-2022-0492 kernel: cgroups v1 release_agent feature may allow privilege escalation
Affected: Red Hat Enterprise Linux 8
https://bugzilla.redhat.com/show_bug.cgi?id=2051505Vendor Advisories for CVE-2022-0492(20)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2022:5157Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security and bug fix update
- RHSA-2022:4717Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security update
- RHSA-2022:4721Red Hat Product SecurityHigh
Red Hat Security Advisory: kpatch-patch security update
- RHSA-2022:4644Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel-rt security and bug fix update
- RHSA-2022:4642Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security and bug fix update
- RHSA-2022:4655Red Hat Product SecurityHigh
Red Hat Security Advisory: kpatch-patch security update
- RHSA-2022:2211Red Hat Product SecurityHigh
Red Hat Security Advisory: kpatch-patch security update
- RHSA-2022:2186Red Hat Product SecurityHigh
Red Hat Security Advisory: kernel security and bug fix update
- +12 more
Patch Availability(23)
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(5)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Microsoft MSRCCVE-2022-04922022-03-16
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw under certain circumstances allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
- Red HatRHSA-2022:0819IMPORTANT2022-02-07
RHSA-2022:0819 — Important
- Red HatRHSA-2022:0821IMPORTANT2022-02-07
RHSA-2022:0821 — Important
- UbuntuLSN-0085-1HIGH
Kernel Live Patch Security Notice
- UbuntuLSN-0086-1HIGH
Kernel Live Patch Security Notice
Data Freshness Timeline
(refreshed 65× in last 7d / 259× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 455 total refreshes for this CVE.
- 2026-07-23 02:06 UTCEG score recompute
- 2026-07-22 22:11 UTCEG score recompute
- 2026-07-22 22:11 UTCVendor advisory
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 18:28 UTCVendor advisory
- 2026-07-22 14:46 UTCEG score recompute
- 2026-07-22 14:46 UTCVendor advisory
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-22 11:03 UTCVendor advisory
- 2026-07-22 07:20 UTCVendor advisory
- 2026-07-22 03:37 UTCVendor advisory
- 2026-07-21 23:53 UTCVendor advisory
- 2026-07-21 18:01 UTCEG score recompute
- 2026-07-21 18:01 UTCVendor advisory
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 14:18 UTCVendor advisory
- 2026-07-21 10:36 UTCVendor advisory
- 2026-07-21 06:52 UTCVendor advisory
- 2026-07-21 03:11 UTCVendor advisory
- 2026-07-20 23:29 UTCVendor advisory
- 2026-07-20 19:47 UTCEG score recompute
- 2026-07-20 19:47 UTCVendor advisory
- 2026-07-20 17:05 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-07-20 16:05 UTCVendor advisory
- 2026-07-20 12:22 UTCVendor advisory
- 2026-07-20 08:39 UTCVendor advisory
- 2026-07-20 04:58 UTCVendor advisory
- 2026-07-20 01:15 UTCVendor advisory
- 2026-07-19 21:33 UTCVendor advisory
- 2026-07-19 17:51 UTCEG score recompute
- 2026-07-19 17:51 UTCVendor advisory
- 2026-07-19 14:29 UTCEPSS rescore
- 2026-07-19 14:09 UTCVendor advisory
- 2026-07-19 10:28 UTCVendor advisory
- 2026-07-19 06:46 UTCVendor advisory
- 2026-07-19 03:04 UTCEG score recompute
- 2026-07-19 03:04 UTCVendor advisory
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-18 23:22 UTCVendor advisory
- 2026-07-18 19:39 UTCVendor advisory
- 2026-07-18 15:57 UTCVendor advisory
- 2026-07-18 12:15 UTCEG score recompute
- 2026-07-18 12:15 UTCVendor advisory
- 2026-07-18 10:02 UTCEPSS rescore
- 2026-07-18 08:33 UTCVendor advisory
- 2026-07-18 04:51 UTCVendor advisory
- 2026-07-18 01:07 UTCVendor advisory
- 2026-07-17 21:25 UTCVendor advisory
- 2026-07-17 17:43 UTCVendor advisory
- 2026-07-17 14:00 UTCVendor advisory
- 2026-07-17 10:18 UTCEG score recompute
- 2026-07-17 10:18 UTCVendor advisory
- 2026-07-17 06:36 UTCVendor advisory
- 2026-07-17 02:54 UTCVendor advisory
- 2026-07-16 23:12 UTCVendor advisory
- 2026-07-16 19:30 UTCVendor advisory
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-16 15:48 UTCVendor advisory
- 2026-07-16 12:05 UTCVendor advisory
- 2026-07-16 08:22 UTCVendor advisory
- 2026-07-16 04:41 UTCVendor advisory
- 2026-07-16 00:59 UTCVendor advisory
- 2026-07-15 21:17 UTCVendor advisory
- 2026-07-15 17:35 UTCVendor advisory
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 13:53 UTCVendor advisory
- 2026-07-15 10:11 UTCVendor advisory
- 2026-07-15 06:28 UTCVendor advisory
- 2026-07-15 02:46 UTCVendor advisory
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-07-14 23:04 UTCVendor advisory
- 2026-07-14 19:22 UTCVendor advisory
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 15:38 UTCVendor advisory
- 2026-07-14 11:56 UTCVendor advisory
- 2026-07-14 08:15 UTCVendor advisory
- 2026-07-14 04:32 UTCVendor advisory
- 2026-07-14 00:50 UTCVendor advisory
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 21:08 UTCVendor advisory
- 2026-07-13 17:26 UTCVendor advisory
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 13:44 UTCVendor advisory
- 2026-07-13 10:02 UTCVendor advisory
- 2026-07-13 06:13 UTCVendor advisory
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-13 02:31 UTCVendor advisory
- 2026-07-12 22:48 UTCVendor advisory
- 2026-07-12 19:06 UTCVendor advisory
- 2026-07-12 15:24 UTCVendor advisory
- 2026-07-12 11:42 UTCVendor advisory
Publicly available exploits
(7 references)Working exploit code is in the public domain (1 Metasploit module) (6 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCT1erno/CVE-2022-0492-Docker-Breakout-Checker-and-PoCFirst seen Feb 18, 2023
Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)
Open source ↗ - GitHub PoCKianaBin/CVE-2022-0492-Container-EscapeFirst seen Aug 27, 2022
CVE-2022-0492-Container-Escape
Open source ↗ - GitHub PoCyoeelingBin/CVE-2022-0492-Container-EscapeFirst seen Aug 27, 2022
CVE-2022-0492-Container-Escape
Open source ↗ - GitHub PoCchenaotian/CVE-2022-0492First seen Mar 11, 2022
CVE-2022-0492 EXP and Analysis write up
Open source ↗ - GitHub PoCSofianeHamlaoui/CVE-2022-0492-CheckerFirst seen Mar 6, 2022
A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492
Open source ↗ - GitHub PoCPaloAltoNetworks/can-ctr-escape-cve-2022-0492First seen Feb 28, 2022
Test whether a container environment is vulnerable to container escapes via CVE-2022-0492
Open source ↗ - Metasploitexploit/linux/local/docker_cgroup_escape✓ verifiedFirst seen Feb 4, 2022
Docker cgroups Container Escape
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownmsrc · redhat
Frequently asked(6)
What is CVE-2022-0492?
When was CVE-2022-0492 disclosed?
Is CVE-2022-0492 actively exploited?
What is the CVSS score of CVE-2022-0492?
Which products are affected by CVE-2022-0492?
How do I remediate CVE-2022-0492?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2022-0492
Is Your Infrastructure Affected by CVE-2022-0492?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.