Evidence dossier

CVE-2022-0492

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function.

Exploited in the wild (CISA KEV since Jun 2, 2026). NVD reports CVSS 3.1 7.8. EPSS estimates 5.5% exploit likelihood as of Aug 27, 2026.

74.674.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

State
PUBLISHED
Published
Mar 3, 2022
Updated
Jun 3, 2026
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    redhat

    Record text: A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

    Inspect raw assertion
    Field
    container
    Value
    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Linux Kernel Improper Authentication Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Linux Kernel Improper Authentication Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 5.53% probability · 92.23th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.055280000000; percentile 0.922330000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jun 2, 2026 · first observed Jul 19, 2026

Exploit likelihood5.53%

FIRST EPSS · score date Aug 27, 2026 · 92.2th percentile · first observed Aug 27, 2026

SeverityCVSS 7.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
redhatOriginal assertion
Record text

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

Inspect raw assertion
Field
container
Value
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Linux Kernel Improper Authentication Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Linux Kernel Improper Authentication Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

5.53% probability · 92.23th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.055280000000; percentile 0.922330000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
53Underlying assertions
33Canonical products
47Target assertions
6Constraint assertions

Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

34 scope groups

redhat · source assertedn/akernelDirect source scope
Affected: kernel 5.17 rc3
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "kernel 5.17 rc3"}]
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 5 assertions
Version 14.04; Version 16.04; Version 18.04; Version 20.04; Version 22.04Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    815d70a8-47d3-459c-a32c-9feaca0659d1
  2. cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
  3. cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    902b8056-9e37-443b-8905-8aa93e2447fb
  4. cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    23a7c53f-b80f-4e6a-afa9-58eea84be11d
  5. cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    359012f1-2c63-415a-88b8-6726a87830de
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 3 assertions
Version 10.0; Version 11.0; Version 9.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa6feec2-9f11-4643-8827-749718254fed
  2. cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    deece5fc-cacf-4496-a3e7-164736409252
  3. cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07b237a9-69a3-4a9c-9da0-4e06bd37ae73
NVD CPE · OPERATING SYSTEMfedoraprojectfedoraVulnerable target · 1 assertions
Version 35Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80e516c0-98a4-4ade-b69f-66a772e2baaa
NVD CPE · OPERATING SYSTEMlinuxlinux_kernelVulnerable target · 9 assertions
Any version (unconstrained) (>= 2.6.24, < 4.9.301); Any version (unconstrained) (>= 4.10, < 4.14.266); Any version (unconstrained) (>= 4.15, < 4.19.229); Any version (unconstrained) (>= 4.20, < 5.4.177); Any version (unconstrained) (>= 5.11, < 5.15.20); Any version (unconstrained) (>= 5.16, < 5.16.6); Any version (unconstrained) (>= 5.5, < 5.10.97); Version 5.17Canonical identity product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e6e34b23-78b4-4516-9bd8-61b33f4ac49a
  2. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 5.16; through excluding 5.16.6
    Match ID
    6739d89e-32c3-479d-b5f6-6865c5061fa5
  3. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 5.5; through excluding 5.10.97
    Match ID
    fb2be440-bf07-4c49-9a0c-a63e4fa103a1
  4. cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7bd5f8d9-54fa-4cb0-b4f0-cb0471fddb2d
  5. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 2.6.24; through excluding 4.9.301
    Match ID
    006c09ff-c563-403e-8723-2a252c409d82
  6. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 5.11; through excluding 5.15.20
    Match ID
    c68fc5b4-cc13-45e9-8050-ef9025f7a9b7
  7. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 4.20; through excluding 5.4.177
    Match ID
    b42832a3-1d9b-4be0-8d4c-3af681b52d98
  8. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 4.15; through excluding 4.19.229
    Match ID
    e67eaacb-63bb-41e7-9fe0-ec45ecd8cfd0
  9. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 4.10; through excluding 4.14.266
    Match ID
    c53477e7-1ab3-4ccb-ba3a-8ca6d288b41b
NVD CPE · OPERATING SYSTEMnetappbootstrap_osVulnerable target · 1 assertions
Version not applicableCanonical identity product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    95ba156c-c977-4f0c-8dfb-3fae9cc8c02d
NVD CPE · HARDWAREnetapph300sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f9c8c20-42eb-4ab5-bd97-212deb070c43
NVD CPE · OPERATING SYSTEMnetapph300s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6770b6c3-732e-4e22-bf1c-2d2fd610061c
NVD CPE · HARDWAREnetapph410cEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cddf61b7-ec5c-467c-b710-b89f502cd04f
NVD CPE · OPERATING SYSTEMnetapph410c_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    234defe0-5ce5-4b0a-96b8-5d227cb8ed31
NVD CPE · HARDWAREnetapph410sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8497a4c9-8474-4a62-8331-3fe862ed4098
NVD CPE · OPERATING SYSTEMnetapph410s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0b4ad8a-f172-4558-aec6-ff424ba2d912
NVD CPE · HARDWAREnetapph500sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e63d8b0f-006e-4801-bf9d-1c001bbfb4f9
NVD CPE · OPERATING SYSTEMnetapph500s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7fff7106-ed78-49ba-9ec5-b889e3685d53
NVD CPE · HARDWAREnetapph700sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-fcd38a3bd0a96c349925cecfd0d22ecf9836f21d88da8f545d6938975aa84275Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b06f4839-d16a-4a61-9bb5-55b13f41e47f
NVD CPE · OPERATING SYSTEMnetapph700s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    56409cec-5a1e-4450-aa42-641e459cc2af
NVD CPE · HARDWAREnetapphci_compute_nodeEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ac128f79df6958432aba953aa4fde55d70b2ccbfc258439c013b541010526631Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad7447bc-f315-4298-a822-549942fc118b
NVD CPE · APPLICATIONnetappsolidfire,_enterprise_sds_&_hci_storage_nodeVulnerable target · 1 assertions
Version not applicableCanonical identity product-bbbe221c2caf7490207f416926c8109f1021c8b7aa8ac57c9b3bc586b9d95462Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:solidfire\,_enterprise_sds_\&_hci_storage_node:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    daa3919c-b2b1-4cb5-ba76-7a079aaffc52
NVD CPE · APPLICATIONnetappsolidfire_&_hci_management_nodeVulnerable target · 1 assertions
Version not applicableCanonical identity product-1ae8307aa63072bc66611f9ee64dfe4cdf453bdf11b115e7e577c4f59a6f282eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6d700c5-f67f-4ffb-be69-d524592a3d2e
NVD CPE · APPLICATIONredhatcodeready_linux_builderVulnerable target · 2 assertions
Version 8.0; Version 8.2Canonical identity product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    93a089e2-d66e-455c-969a-3140d991baf4
  2. cpe:2.3:a:redhat:codeready_linux_builder:8.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    af2ff4aa-3027-4f30-9f2a-3e820bba8bf0
NVD CPE · APPLICATIONredhatcodeready_linux_builder_for_power_little_endianVulnerable target · 2 assertions
Version 8.0; Version 8.2Canonical identity product-dce6b2225fa5e56152bdc66540e68bf243b135fd00684a7262378fbfd0331e98Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f48d0cb-cb06-4456-b918-6549bc6c7892
  2. cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian:8.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f15192f-c162-4d4f-abbc-7ce66bd923a2
NVD CPE · OPERATING SYSTEMredhatenterprise_linuxVulnerable target · 1 assertions
Version 8.0Canonical identity product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f4cff558-3c47-480d-a2f0-babf26042943
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 1 assertions
Version 8.2Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    831f0f47-3565-4763-b16f-c87b1ff2035e
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systemsVulnerable target · 1 assertions
Version 8.0Canonical identity product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    87c21fe1-ea5c-498f-9c6c-d05f91a88217
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systems_eusVulnerable target · 1 assertions
Version 8.0Canonical identity product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4ae1552c-9398-4952-ad8c-777df9587043

Affected-product evidence

Accepted scope and product mapping

27 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9

Source class
Nvd cpe vulnerable target
Assertions
9
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
27db53b6-59fe-456b-86ea-6dd12b8e6da328ae17d7-a973-4938-a8e2-9c1ae3be6fef484d8bba-ed32-49ac-96f8-e015f5adac1e4fabc3f8-6434-431b-9d9a-35e3d7b5f34e5c89aef9-1bf1-43e0-ad60-ca479b4a7c2a79f4d4b7-5fd8-4029-a51f-5028985f76f6ab8be702-d3ae-4b89-a264-3f2e2feb10e5ca83b4ad-7429-4190-a559-ddb90221b634ff87dfda-4a11-4de8-8707-d47ce6dc89e2
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1ae8307aa63072bc66611f9ee64dfe4cdf453bdf11b115e7e577c4f59a6f282e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
aad7d8ac-897d-42c3-bdf6-32d0c9e35e1f
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
04e727f2-cc09-46e4-923c-cf2f33aa16ca
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c0ecc2b8-c38e-478d-a374-69a1aade6be2
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0f6b9a04-5dbb-44f4-bca0-3cce88c46a1d
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
146c239a-0b09-4fe7-be63-4a696b7606d015b31b6c-831a-4e33-a52c-88ca6ba9d18660ed0599-1ff8-4cba-9a25-842a9294f7f1
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
82ccb813-85e7-4ce7-b011-637427db6d45
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-47dee1744bced301ddbc92cf5cc13b521975487b8f5b36604aaffd87a1ae790b

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4491dd00-004e-48f7-8553-0c26182efa4ade77948f-5b00-41c5-b50a-36f0741eb089
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1e73bd2d-806c-4c0e-9599-e968c8eece0e54c59bd7-5f54-4a67-8144-d0970432addc
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-6077d17fbbe710b7e004df2ce68ca2ecda6ca6818bc290d21e2eb259438463ba

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ca10130e-27ac-45b3-b952-dce77cca58c9
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-620fb96b7f8c3dad1ed3a016e96da2a9a5a83898e74776d63b998d9fe84efa9f

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
13dd70a4-004b-48cc-b6a0-1af259e9b1b17d5d88db-4e68-4125-b18b-4b6d9581ac2e
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
060cd683-63f5-4450-867d-03969a939e54
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
46a57035-b550-4769-b685-ff11788001828ad7f5ef-eaa0-4e05-bed5-a4673e12c2da
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
218d8d48-e993-4194-8d3f-8764b48f6d84
Mapping establishedEvidence supported

vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
16097ef0-3198-423a-afc0-967bbb2e955454b5973c-f6c5-47b3-b8c7-8e785d360a208baefa99-50b4-488d-9140-bc1662abbf1897d2d9e4-37d3-46d8-b6a5-93a7e7b5491dcf9d5946-c2ec-4161-b546-cecbea600ed6
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5d47acac-e35f-4366-b3a3-2ccc6beb8939
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-bbbe221c2caf7490207f416926c8109f1021c8b7aa8ac57c9b3bc586b9d95462

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
136f0197-4607-4a00-8a52-80c1c5b1c39b
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b0d9ecaa-31e9-474c-95b7-b071751b5b87
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c9e6b813-9846-470d-903d-65eecef561e5
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
319215ba-d6be-4501-8013-03ed310957ac
Mapping establishedEvidence supported

vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ed302057-72aa-40c5-bb5f-6c2b12dda68c
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b799c369-da65-4064-a137-0467ccaed3ca
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d77cc1a1fefec2e8775cda418005f8915bf7c83bb7052bf25df4ce37b5cf7cce

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d8769a47-71a1-4bce-b0ca-e163a9c2c2ececdced92-603d-4f9e-bf83-797eedbfd75a
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-dce6b2225fa5e56152bdc66540e68bf243b135fd00684a7262378fbfd0331e98

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
094333b2-f133-4369-b7aa-dd23afa01151495637e8-d4be-48ce-b28f-eea2dc694dde
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
24eb29a4-f324-4ba5-bd3f-3048876d711f
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d1de68f4-2dad-45ce-b1b0-74747a10fed4
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
11fa3b9a-505a-4aa0-af74-2f9d107aebac
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8d653024-9a46-4058-9adb-84b08c6d9642

Assessments

CVSS by origin

7.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
6.9
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:L/AC:M/Au:N/C:C/I:C/A:C
7.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

7.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
7.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.