[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_P5KxTcNGj-axTY5ewhq9dcSoJogJhcreF92pyB5JNk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"46f32b2c-dced-4863-804a-0a5002812ae1","critical-linux-kernel-vulnerability-exploited-after-years-of-public-disclosure","2edcce78-a7d6-49ce-aba7-f4dd5b77c172","Critical Linux Kernel Vulnerability Exploited After Years of Public Disclosure","CVE-2022-0492 demonstrates the dangerous gap between vulnerability disclosure and patching, as this Linux kernel flaw was exploited in the wild despite technical details being public for three years. The vulnerability allows unprivileged users to escalate privileges to root and escape containers by manipulating the cgroups v1 release_agent file. Organizations that delayed patching left themselves vulnerable to complete system compromise, highlighting the critical importance of timely security updates for kernel-level vulnerabilities.","**Immediate actions:**\n- Apply the Linux kernel patch for CVE-2022-0492 immediately on all affected systems\n- Audit container configurations and disable cgroups v1 if cgroups v2 is available\n- Scan all Linux systems for this vulnerability using automated tools\n\n**Long-term improvements:**\n- Implement automated patch management with prioritization for kernel vulnerabilities\n- Establish maximum patching timeframes based on vulnerability severity and exposure\n- Maintain complete inventory of all Linux systems and kernel versions across the organization\n\n**Detection measures:**\n- Monitor for unauthorized modifications to cgroups release_agent files\n- Implement container runtime security monitoring to detect escape attempts\n- Enable audit logging for privilege escalation events on Linux systems",[12,13,14,15,16,17],"CIS Control 7","NIST CM-3","NIST SI-2","CIS Control 2","NIST RA-5","CISA BOD 22-01","published","2026-06-03T12:06:41.515118+00:00","2026-06-03T12:06:41.453+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Forganizations-warned-of-exploited-linux-kernel-vulnerability\u002F","organizations-warned-of-exploited-linux-kernel-vulnerability-b73a85","Organizations Warned of Exploited Linux Kernel Vulnerability",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"1dc1f669-6555-4116-bc32-dda32199dd59","2026-06-03","afternoon","ThreatNoir Afternoon Brief — June 3","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-03\u002Fthreatnoir-afternoon-brief-2026-06-03.mp3"]