Vulnerability  ·  2026-06-03

CISA KEV: CVE-2022-0492 — Linux Kernel cgroups v1 Privilege Escalation Added to Known Exploited Vulnerabilities Catalog

VulnerabilityHigh impactGlobalCVE-2022-0492
The Linux kernel contains an improper authentication vulnerability allowing privilege escalation via the cgroups v1 release_agent feature. An attacker with local access can abuse this to escape container boundaries or escalate to root. CISA added this to the KEV catalog on June 2, 2026, confirming in-the-wild active exploitation. This vulnerability is directly relevant to AI infrastructure: containerized LLM inference servers (vLLM, Ollama, LiteLLM, Ray), ML training clusters, and Kubernetes-orchestrated AI workloads running on older kernel versions are all at risk.
Local privilege escalation via manipulation of the cgroups v1 release_agent feature in the Linux kernel. Can be used to escape container isolation in AI serving infrastructure running on vulnerable kernel versions.
Linux Kernel (all distributions with cgroups v1 enabled, unpatched). AI serving infrastructure running on Linux containers or Kubernetes is particularly exposed — containerized vLLM, Ollama, LiteLLM, and Ray deployments on unpatched hosts.
Apply vendor kernel patches per Linux distribution. Federal agencies must remediate by June 5, 2026 per BOD 22-01. For cloud/AI infra teams: update kernel packages on all AI serving hosts; audit Kubernetes node versions; consider disabling cgroups v1 release_agent if not required. Verify container runtime versions are not inherently vulnerable.
Sources
CISA — Known Exploited Vulnerabilities CatalogNVD — CVE-2022-0492
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →