{"id":13443,"date":"2026-06-07T10:03:50","date_gmt":"2026-06-07T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/07\/cisa-warns-of-linux-kernel-improper-authentication-vulnerability-exploited-in-attacks\/"},"modified":"2026-06-07T10:03:50","modified_gmt":"2026-06-07T10:03:50","slug":"cisa-warns-of-linux-kernel-improper-authentication-vulnerability-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/07\/cisa-warns-of-linux-kernel-improper-authentication-vulnerability-exploited-in-attacks\/","title":{"rendered":"CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks"},"content":{"rendered":"<p>    CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical <a href=\"https:\/\/cybersecuritynews.com\/nine-year-old-linux-kernel-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Linux kernel vulnerability<\/a>, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks.<\/p>\n<p class=\"wp-block-paragraph\">The issue, categorized as improper authentication, affects Linux systems using the cgroups v1 release_agent feature and may allow attackers to achieve privilege escalation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2022-0492 stems from insufficient validation and authentication controls within the Linux kernel\u2019s control groups (cgroups) mechanism.<\/p>\n<p class=\"wp-block-paragraph\">Specifically, the vulnerability enables a local attacker to manipulate the release_agent functionality, which is designed to execute a script when a cgroup becomes empty.<\/p>\n<p class=\"wp-block-paragraph\">By exploiting this behavior, an attacker can execute arbitrary commands with elevated privileges, effectively escaping containerized environments or <a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-released-for-linux-kernel-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">gaining root-level access<\/a> on the host system.<\/p>\n<h2 id=\"h-linux-kernel-improper-authentication-flaw-exploit\" class=\"wp-block-heading\"><strong>Linux Kernel Improper Authentication Flaw Exploit<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Security researchers have noted that this flaw is particularly dangerous in containerized and cloud-native environments where cgroups are widely used for resource isolation.<\/p>\n<p class=\"wp-block-paragraph\">Misconfigured or unpatched systems may allow attackers who have already gained initial access, such as through a compromised container, to break out and take control of the underlying host.<\/p>\n<p class=\"wp-block-paragraph\">This aligns with the broader trend of attackers targeting container escape vulnerabilities to move laterally within cloud infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability is associated with <a href=\"https:\/\/cybersecuritynews.com\/cisa-sharepoint-code-injection\/\" target=\"_blank\" rel=\"noreferrer noopener\">CWE-287 (Improper Authentication)<\/a> and <a href=\"https:\/\/cybersecuritynews.com\/cisa-adds-digiever-authorization-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CWE-862 (Missing Authorization)<\/a>, highlighting inadequate checks for enforcing security boundaries.<\/p>\n<p class=\"wp-block-paragraph\">While there is currently no confirmed public attribution linking CVE-2022-0492 directly to ransomware campaigns, CISA\u2019s inclusion of the flaw in the KEV catalog indicates credible evidence of active exploitation in the wild.<\/p>\n<p class=\"wp-block-paragraph\">CISA has mandated federal agencies to remediate the vulnerability by June 5, 2026, in accordance with Binding Operational Directive (BOD) 22-01.<\/p>\n<p class=\"wp-block-paragraph\">The directive requires agencies to apply vendor-provided patches or mitigations to reduce exposure promptly.<\/p>\n<p class=\"wp-block-paragraph\">Organizations that rely on affected Linux systems are strongly encouraged to follow similar timelines, as delays in patching could increase the risk of compromise.<\/p>\n<p class=\"wp-block-paragraph\">Mitigation measures include updating the <a href=\"https:\/\/cybersecuritynews.com\/google-patched-linux-kernel-vulnerability-in-android\/\" target=\"_blank\" rel=\"noreferrer noopener\">Linux kernel to a patched<\/a> version that addresses the release_agent issue, turning off unprivileged user namespaces where feasible, and restricting access to cgroup configurations.<\/p>\n<p class=\"wp-block-paragraph\">Security teams should also audit container environments and monitor for suspicious activity related to cgroup manipulation, as this may indicate attempted exploitation.<\/p>\n<p class=\"wp-block-paragraph\">The<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> addition of CVE-2022-0492 to the KEV catalog<\/a> underscores the ongoing risk posed by privilege-escalation vulnerabilities in widely deployed open-source components.<\/p>\n<p class=\"wp-block-paragraph\">As attackers increasingly target foundational technologies like the Linux kernel, timely patching and proactive monitoring remain essential to defending enterprise and cloud environments against evolving threats.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/linux-kernel-improper-authentication-vulnerability\/\">CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/linux-kernel-improper-authentication-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The issue, categorized as improper authentication, affects Linux [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,406,648],"tags":[130],"class_list":["post-13443","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-linux","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13443"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13443"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13443\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}