Details have emerged about a now-patched high-severity vulnerability in the Linux kernel that could potentially be abused to escape a container in order to execute arbitrary commands on the container host. . The shortcoming resides in a Linux kernel feature called control groups , also referred to as cgroups version 1 (v1), which allows processes to be organized into hierarchical groups, thereby making it possible to limit and monitor the usage of resources such as CPU, memory, disk I/O, and network. Tracked as CVE-2022-0492 (CVSS score: 7.0), the issue concerns a case of privilege escalation in the cgroups v1 release_agent functionality, a script that's executed following the termination of any process in the cgroup. The link for this article located at The Hacker News is no longer available. . A high-severity kernel vulnerability, CVE-2023-XXXX, allows container escape and unauthorized command execution, urging users to apply security patches promptly.. Container Escape, Linux Kernel Security, Privilege Escalation. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.