Missing Authorization Affecting kernel-livepatch-5_3_18-24_67-default package, versions <11-150200.2.1
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES152-KERNELLIVEPATCH53182467DEFAULT-3265226
- published 14 Apr 2022
- disclosed 29 Mar 2022
Introduced: 29 Mar 2022
CVE-2022-0492 Open this link in a new tabHow to fix?
Upgrade SLES:15.2 kernel-livepatch-5_3_18-24_67-default to version 11-150200.2.1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-livepatch-5_3_18-24_67-default package and not the kernel-livepatch-5_3_18-24_67-default package as distributed by SLES.
See How to fix? for SLES:15.2 relevant fixed versions and status.
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
References
- https://www.suse.com/security/cve/CVE-2022-0492.html
- https://bugzilla.suse.com/1195543
- https://bugzilla.suse.com/1195908
- https://bugzilla.suse.com/1196612
- https://bugzilla.suse.com/1196776
- https://bugzilla.suse.com/1198615
- https://bugzilla.suse.com/1199255
- https://bugzilla.suse.com/1199615
- https://bugzilla.suse.com/1200084
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af
- https://bugzilla.redhat.com/show_bug.cgi?id=2051505
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html
- https://www.debian.org/security/2022/dsa-5096
- https://www.debian.org/security/2022/dsa-5095
- http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html
- https://security.netapp.com/advisory/ntap-20220419-0002/
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
- http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html