LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 2, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-0492 to its Known Exploited Vulnerabilities catalog on Jun 2, 2026, with a federal patch deadline of Jun 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

This vulnerability affects the Linux Kernel and stems from an improper authentication issue that could allow privilege escalation through the cgroups v1 release_agent feature. Systems running the Linux kernel are common in servers, containers, and cloud workloads, so successful exploitation could let an attacker obtain higher privileges than intended.

How it works

The flaw is described by CWE-287 and CWE-862, which cover improper authentication and missing authorization checks. In this case the weakness centers on the cgroups v1 release_agent feature.

An attacker who can influence cgroup configuration may be able to trigger actions that bypass intended permission boundaries and obtain elevated privileges on the host.

Am I affected? How to find it in your systems

Linux kernels are present on physical servers, virtual machines, and container hosts. Begin by inventorying all systems that run a Linux kernel, including those managed through orchestration platforms.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review configurations that involve cgroups v1 and remove or restrict use of the release_agent feature where it is not required.

If you can't patch immediately

Follow the mitigations listed in the vendor advisory. Where cloud services are involved, apply any applicable BOD 22-01 requirements. Segment affected systems so that a successful escalation cannot easily reach other workloads, and consider disabling the cgroups v1 release_agent capability through kernel boot parameters or runtime configuration if supported.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to unauthorized access and subsequent data exposure in other incidents. Organizations can run a free exposure scan of their domains and email addresses against known breach data to determine whether any credentials or assets already appear in public breach repositories.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLinux · Kernel
WeaknessCWE-287
Added to CISA KEVJun 2, 2026
Federal patch deadlineJun 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities