Red Hat released Important RHEL kernel updates addressing multiple Linux kernel flaws, including CVE-2022-0492, in which abuse of the cgroups v1 release_agent feature can enable local privilege escalation and bypass namespace isolation, creating a container-escape path. The upstream fix is tracked in commit 24f6008564183aa120d07c03d9289519c2fe02af; related kernel issues include CVE-2022-0847 (Dirty Pipe), file-descriptor handling defects, missing TLB flushing, usercopy use-after-free conditions, kernel memory read/write flaws, and TIPC denial of service.
Affected updates include RHEL 8 kernel 4.18.0-348.20.1.el8_5 across x86_64, ARM64, IBM Z, and Power LE variants, as well as kernel-rt packages for RHEL 8.2 Real Time Telecommunications and NFV Telecommunications Update Service on x86_64. Organizations should apply the applicable updated kernel packages and reboot hosts to activate the fixes. Red Hat assessed OpenShift Container Platform clusters with SELinux enabled by default as protected against the CVE-2022-0492 container-escape and privilege-escalation path.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2022:2186 for RHEL 7.6 AUS, TUS, and SAP Update Services offerings. The reboot-required kernel 3.10.0-957.94.1.el7 update remediated CVE-2022-0492 and the RDMA listen() use-after-free flaw CVE-2021-4028.
Red Hat issued Important advisory RHSA-2022:2211, providing updated kpatch-patch live kernel modules for supported RHEL 7.6 offerings on x86_64 and ppc64le. The update remediated CVE-2022-0492 and the RDMA listen() use-after-free vulnerability CVE-2021-4028.
Red Hat issued Important advisory RHSA-2022:1455 for RHEL 8.4 Extended Update Support and related offerings, providing kernel 4.18.0-305.45.1.el8_4 for x86_64, s390x, ppc64le, and aarch64. The reboot-required update remediated CVE-2022-0492, CVE-2021-4083, and CVE-2022-25636.
Red Hat issued Important advisory RHSA-2022:1413 for RHEL 8.4 Extended Update Support real-time offerings on x86_64. The kernel-rt 4.18.0-305.45.1.rt7.117.el8_4 update fixed CVE-2022-0492 along with CVE-2021-4083 and CVE-2022-25636, and required a reboot.
Red Hat issued Important advisory RHSA-2022:0825, updating RHEL 8 kernels to version 4.18.0-348.20.1.el8_5 across supported architectures and service variants. The update remediated eight vulnerabilities, including CVE-2022-0492, and required systems to be rebooted after installation.
Red Hat issued Important advisory RHSA-2022:0821 for RHEL 8.2 Extended Update Support real-time products on x86_64. It provided kernel-rt 4.18.0-193.79.1.rt13.129.el8_2, fixing CVE-2022-0492, Dirty Pipe (CVE-2022-0847), and three other kernel flaws.
Red Hat assessed OpenShift Container Platform clusters with the default SELinux policy enabled on nodes as not affected by the CVE-2022-0492 container-escape and privilege-escalation path.
Fedora incorporated the CVE-2022-0492 fix into its stable Linux kernel version 5.16.6.
The upstream Linux kernel fixed CVE-2022-0492, a cgroups v1 release_agent flaw that could enable privilege escalation and namespace-isolation bypass, in commit 24f6008564183aa120d07c03d9289519c2fe02af.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.