# Linux Kernel cgroups v1 release_agent Container Escape & Privilege Escalation (CVE-2022-0492) — Added to CISA KEV (Active Exploitation)

> CVE-2022-0492 is an improper-authorization flaw in the Linux kernel's cgroup_release_agent_write function (kernel/cgroup/cgroup-v1.c) that lets an attacker abuse the cgroups v1 release_agent feature to execute arbitrary code as root in the initial namespace, enabling container escape and local privilege escalation. CISA added it to the Known Exploited Vulnerabilities Catalog on 2026-06-02 citing evidence of active exploitation; FCEB agencies must remediate under BOD 22-01.

- **Published:** 2026-06-02T00:00:00Z
- **Last reviewed:** 2026-06-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0662
- **ID:** TL-2026-0662
- **Severity:** CRITICAL (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2022-0492

## Description

CVE-2022-0492 is a privilege-escalation and container-escape vulnerability in the Linux kernel's cgroups (control groups) version 1 subsystem. The flaw resides in cgroup_release_agent_write() in kernel/cgroup/cgroup-v1.c, which handles writes to the per-cgroup 'release_agent' file. The release_agent feature instructs the kernel to execute a specified binary — as full root in the initial (host) namespace — whenever the last task leaves a cgroup that has notify_on_release=1. Before the fix, the write handler failed to verify that the writing process held the appropriate capability (CAP_SYS_ADMIN) over the initial user namespace that owns the cgroup filesystem. The kernel only confirmed the caller was 'capable' in some namespace, not that it was authorized over the resource being modified. This is classed as CWE-287 (Improper Authentication) and CWE-862 (Missing Authorization).

Because an unprivileged user on most modern Linux distributions can create a new user namespace via unshare(CLONE_NEWUSER) and obtain CAP_SYS_ADMIN inside it, then mount a cgroup v1 hierarchy (e.g. the RDMA controller) within a new mount+cgroup namespace, the attacker can write an arbitrary path into release_agent and force the kernel to run it as root on the host. There are two principal exploitation scenarios. (1) Bare-host local privilege escalation: an unprivileged user escalates to root by chaining unshare -UrmC, mounting cgroupfs, writing a payload path to release_agent, setting notify_on_release, and triggering cgroup release. (2) Container escape: a container process that holds CAP_SYS_ADMIN (or can acquire it via user-namespace creation) and is not confined by an enforcing AppArmor or SELinux policy can break out to the host by the same release_agent mechanism, resolving the host-side path of its overlay/upperdir from /etc/mtab or /proc/self/cgroup so the dropped script is reachable from the root mount namespace.

The exploitation primitive is the long-known 'privileged container' release_agent escape, but CVE-2022-0492 broadened the exposure: the missing authorization check meant the technique was reachable in configurations previously believed safe, and reliably from an unprivileged user-namespace context. Public proof-of-concept code is widely available and the technique is trivially weaponized (a few shell commands), which is consistent with CISA's active-exploitation determination. Post-escape, an attacker operating as host root can read host secrets and mounted volumes, establish persistence, deploy additional containers, and move laterally across the cluster or host fleet.

Critical mitigating factors: an enforcing AppArmor profile (e.g. Docker's default docker-default profile, which denies writes to release_agent) or SELinux in enforcing mode blocks the write or the subsequent execution; dropping CAP_SYS_ADMIN from containers removes the primary path; and seccomp policies that block the unshare/mount syscalls neutralize the unprivileged-user variant. The upstream fix (commit 24f6008564183aa120d07c03d9289519c2fe02af, 'cgroup-v1: Require capabilities to set release_agent') adds an ns_capable() check requiring CAP_SYS_ADMIN over the user namespace that owns the cgroup filesystem, plus a check that the opener of the file is privileged. The flaw was reported by Yiqi Sun and Kevin Wang and analyzed in depth by Palo Alto Networks Unit 42. Fixed in Linux 5.17 and backported to stable trees (5.16.5, 5.15.19, 5.10.96, 5.4.176, 4.19.228, 4.14.265, 4.9.300) and to enterprise kernels by Red Hat, SUSE, Ubuntu, and Debian.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1609 Container Administration Command
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1611 Escape to Host
- T1548 Abuse Elevation Control Mechanism
- T1211 Exploitation for Stealth
- T1222 File and Directory Permissions Modification
- T1552.001 Unsecured Credentials: Credentials In Files
- T1082 System Information Discovery
- T1613 Container and Resource Discovery
- T1021 Remote Services

## Sources

- [CISA Adds Two Known Exploited Vulnerabilities to Catalog](https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [NVD - CVE-2022-0492](https://nvd.nist.gov/vuln/detail/CVE-2022-0492)
- [Unit 42: New Linux Vulnerability CVE-2022-0492 Affecting cgroups - Can Containers Escape?](https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/)
- [Red Hat Bugzilla #2051505 - CVE-2022-0492](https://bugzilla.redhat.com/show_bug.cgi?id=2051505)
- [Upstream patch: cgroup-v1: Require capabilities to set release_agent](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af)
- [Debian Security Advisory DSA-5095-1 linux](https://www.debian.org/security/2022/dsa-5095)
- [Docker cgroups Container Escape (Packet Storm)](http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0662
