peter bassill · operator
$ cve CVE-2022-0995 JSON

CVE-2022-0995 KEV

7.8
HIGH · CVSS 3.1 · EPSS 8.8% (pctl 95)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-09.

Description

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS8.79% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2026-09-09
Public exploitnone known
Published2022-03-25
Last modified2026-08-27

CISA KEV

NameLinux Kernel Out-of-Bounds Write Vulnerability
Added2026-08-26
Due2026-09-09
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (24)

VendorProduct
fedoraprojectfedora
linuxlinux kernel
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph610c
netapph610c firmware
netapph610s
netapph610s firmware
netapph615c
netapph615c firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware

References

→ the Explorer  ·  watch your stack  ·  NVD