Database/Kernel, userspace & hypervisor
Linux kernel (cgroups v1): cgroups v1 release_agent lets a container with CAP_SYS_ADMIN (or an unconfined userns) run
Impact
cgroups v1 release_agent lets a container with CAP_SYS_ADMIN (or an unconfined userns) run arbitrary host-root commands [KEV]
Who can reach it
Any tenant process in a container
What to do
Livepatchable; otherwise drain + reboot. Strong compensating controls: cgroup v2 only, seccomp/AppArmor default profiles, drop CAP_SYS_ADMIN
Fleet impact
How widespread
Universal - the release_agent path exists on every pre-5.17 kernel; cgroups v1 was still the default on most GPU host images
Cost to remediate
node-reboot - kernel upgrade; the only mitigation is relying on AppArmor/SELinux/seccomp being correctly applied, which is exactly what privileged AI workloads often disable
Why it hits the whole fleet
A root-in-container process abuses user namespaces to mount cgroups v1, sets release_agent and runs arbitrary commands as host root; GPU containers routinely run privileged or with --cap-add, which removes the default hardening that would have blocked it
References
Related entries
- Linux kernel (io_uring): Use-after-free between io_uring and the unix GC - local rootCVE-2022-2602 · Linux kernel (io_uring)High
- Linux kernel (OverlayFS/FUSE): OverlayFS copies setuid files from a nosuid FUSE mountCVE-2023-0386 · Linux kernel (OverlayFS/FUSE)High
- Linux kernel (arch/s390/pci): When an SR-IOV VF is hot-unplugged its MMIO resources are freed, but the parent bus keepsCVE-2023-53123 · Linux kernel (arch/s390/pci)High
- Linux kernel (perf): Out-of-bounds write in perf_read_group() via read_size overflow - local rootCVE-2023-6931 · Linux kernel (perf)High
- Linux kernel (IGMP): Use-after-free in IPv4 IGMP - local privilege escalationCVE-2023-6932 · Linux kernel (IGMP)High
- Linux kernel (kTLS): splice() into a kTLS socket overwrites read-only kernel pages - local privilege escalationCVE-2024-0646 · Linux kernel (kTLS)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.