A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 78.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| VPI | 100.00 |
VPI formula vpi-v1
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
| Source | CVSS Version | Base Score | Severity | Vector String | Assessment Date |
|---|---|---|---|---|---|
| NVDNIST | 2.0 | 6.9 | MEDIUM | AV:L/AC:M/Au:N/C:C/I:C/A:C | 04/20/2026 |
| NVDNIST | 3.1 | 7.8 |
| CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 04/20/2026 |