-
Notifications
You must be signed in to change notification settings - Fork 314
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-0492: flaw in Linux Kernel cgroups feature allows container escape #2834
Comments
@miwithro Any ETA on this please? |
@saffiali it will be in all Azure regions by 3/25 |
Hello! It appears that the fix for CVE-2022-0492 missed it's original release in 5.4.0-1072 and was released in 1073.76: https://launchpad.net/ubuntu/+source/linux-azure-5.4/+changelog It is also pointing to 1073.76 in the CVE database (though, it was originally 1072): https://ubuntu.com/security/CVE-2022-0492 |
@justbert you are right. I updated our guidance. |
Thanks for reaching out. I'm closing this issue as it was marked with "Answer Provided" and it hasn't had activity for 2 days. |
It has been discovered that under certain circumstances, the Linux kernel’s cgroups v1 release_agent feature can be used to escalate privilege and bypass namespace isolation unexpectedly.
https://ubuntu.com/security/CVE-2022-0492
AKS Information:
Update your node image to 2022.03.29 to remediate this vulnerability.
The text was updated successfully, but these errors were encountered: