Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-0492: flaw in Linux Kernel cgroups feature allows container escape #2834

Closed
miwithro opened this issue Mar 9, 2022 · 5 comments
Closed
Labels
announcement resolution/answer-provided Provided answer to issue, question or feedback. security

Comments

@miwithro
Copy link
Contributor

miwithro commented Mar 9, 2022

It has been discovered that under certain circumstances, the Linux kernel’s cgroups v1 release_agent feature can be used to escalate privilege and bypass namespace isolation unexpectedly.

https://ubuntu.com/security/CVE-2022-0492

AKS Information:

Update your node image to 2022.03.29 to remediate this vulnerability.

@miwithro miwithro pinned this issue Mar 9, 2022
@saffiali
Copy link

@miwithro Any ETA on this please?

@miwithro
Copy link
Contributor Author

@saffiali it will be in all Azure regions by 3/25

@justbert
Copy link

justbert commented Mar 24, 2022

Hello!

It appears that the fix for CVE-2022-0492 missed it's original release in 5.4.0-1072 and was released in 1073.76: https://launchpad.net/ubuntu/+source/linux-azure-5.4/+changelog

It is also pointing to 1073.76 in the CVE database (though, it was originally 1072): https://ubuntu.com/security/CVE-2022-0492

@miwithro
Copy link
Contributor Author

@justbert you are right. I updated our guidance.

@miwithro miwithro added the resolution/answer-provided Provided answer to issue, question or feedback. label Apr 22, 2022
@ghost
Copy link

ghost commented Apr 24, 2022

Thanks for reaching out. I'm closing this issue as it was marked with "Answer Provided" and it hasn't had activity for 2 days.

@ghost ghost closed this as completed Apr 24, 2022
@miwithro miwithro unpinned this issue Apr 25, 2022
@ghost ghost locked as resolved and limited conversation to collaborators May 25, 2022
This issue was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
announcement resolution/answer-provided Provided answer to issue, question or feedback. security
Projects
None yet
Development

No branches or pull requests

3 participants