A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.