CRITICAL 01CVE-2022-0492 Linux Kernel cgroup release_agent Added to CISA KEV
CISA added CVE-2022-0492, an improper authentication flaw in the Linux kernel cgroups v1 release_agent mechanism, to the Known Exploited Vulnerabilities Catalog on June 2, 2026. The vulnerability enables local privilege escalation and full container escape on affected hosts.
FCEB agencies must remediate by June 5, 2026 under BOD 22-01. Maps to NIST 800-171 §3.4.2 (baseline configuration) and §3.14.1 (flaw remediation). Container runtime forensic evidence (cgroup mount, release_agent path, audit logs) must be preserved.
