CVE Details

CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
Published: 2026-08-26 CVSS: 7.8 HIGH Product: Linux Kernel Due Date: 2026-09-09

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 7.8
  • Severity: HIGH
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
containers > cna > affected > 0 > product kernel
containers > cna > affected > 0 > vendor n/a
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version kernel 5.17 rc8
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-787
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-787
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > providerMetadata > dateUpdated 2022-04-29T13:07:11.000Z
containers > cna > providerMetadata > orgId 53f830b8-0a3f-465b-8143-3b8a9948e749
containers > cna > providerMetadata > shortName redhat
containers > cna > references > 0 > tags > 0 x_refsource_MISC
containers > cna > references > 0 > url https://bugzilla.redhat.com/show_bug.cgi?id=2063786
containers > cna > references > 1 > tags > 0 x_refsource_MISC
containers > cna > references > 1 > url https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb
containers > cna > references > 2 > tags > 0 x_refsource_MISC
containers > cna > references > 2 > url http://packetstormsecurity.com/files/166770/Linux-watch_queue-Filter-Out-Of-Bounds-Write.html
containers > cna > references > 3 > tags > 0 x_refsource_MISC
containers > cna > references > 3 > url http://packetstormsecurity.com/files/166815/Watch-Queue-Out-Of-Bounds-Write.html
containers > cna > references > 4 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 4 > url https://security.netapp.com/advisory/ntap-20220429-0001/
containers > cna > x_legacyV4Record > CVE_data_meta > ASSIGNER [email protected]
containers > cna > x_legacyV4Record > CVE_data_meta > ID CVE-2022-0995
containers > cna > x_legacyV4Record > CVE_data_meta > STATE PUBLIC
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > product_name kernel
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > version > version_data > 0 > version_value kernel 5.17 rc8
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > vendor_name n/a
containers > cna > x_legacyV4Record > data_format MITRE
containers > cna > x_legacyV4Record > data_type CVE
containers > cna > x_legacyV4Record > data_version 4.0
containers > cna > x_legacyV4Record > description > description_data > 0 > lang eng
containers > cna > x_legacyV4Record > description > description_data > 0 > value An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > lang eng
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > value CWE-787
containers > cna > x_legacyV4Record > references > reference_data > 0 > name https://bugzilla.redhat.com/show_bug.cgi?id=2063786
containers > cna > x_legacyV4Record > references > reference_data > 0 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 0 > url https://bugzilla.redhat.com/show_bug.cgi?id=2063786
containers > cna > x_legacyV4Record > references > reference_data > 1 > name https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb
containers > cna > x_legacyV4Record > references > reference_data > 1 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 1 > url https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb
containers > cna > x_legacyV4Record > references > reference_data > 2 > name http://packetstormsecurity.com/files/166770/Linux-watch_queue-Filter-Out-Of-Bounds-Write.html
containers > cna > x_legacyV4Record > references > reference_data > 2 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 2 > url http://packetstormsecurity.com/files/166770/Linux-watch_queue-Filter-Out-Of-Bounds-Write.html
containers > cna > x_legacyV4Record > references > reference_data > 3 > name http://packetstormsecurity.com/files/166815/Watch-Queue-Out-Of-Bounds-Write.html
containers > cna > x_legacyV4Record > references > reference_data > 3 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 3 > url http://packetstormsecurity.com/files/166815/Watch-Queue-Out-Of-Bounds-Write.html
containers > cna > x_legacyV4Record > references > reference_data > 4 > name https://security.netapp.com/advisory/ntap-20220429-0001/
containers > cna > x_legacyV4Record > references > reference_data > 4 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 4 > url https://security.netapp.com/advisory/ntap-20220429-0001/
containers > adp > 0 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 0 > providerMetadata > shortName CVE
containers > adp > 0 > providerMetadata > dateUpdated 2024-08-02T23:47:42.878Z
containers > adp > 0 > title CVE Program Container
containers > adp > 0 > references > 0 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 0 > tags > 1 x_transferred
containers > adp > 0 > references > 0 > url https://bugzilla.redhat.com/show_bug.cgi?id=2063786
containers > adp > 0 > references > 1 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 1 > tags > 1 x_transferred
containers > adp > 0 > references > 1 > url https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb
containers > adp > 0 > references > 2 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 2 > tags > 1 x_transferred
containers > adp > 0 > references > 2 > url http://packetstormsecurity.com/files/166770/Linux-watch_queue-Filter-Out-Of-Bounds-Write.html
containers > adp > 0 > references > 3 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 3 > tags > 1 x_transferred
containers > adp > 0 > references > 3 > url http://packetstormsecurity.com/files/166815/Watch-Queue-Out-Of-Bounds-Write.html
containers > adp > 0 > references > 4 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 4 > tags > 1 x_transferred
containers > adp > 0 > references > 4 > url https://security.netapp.com/advisory/ntap-20220429-0001/
containers > adp > 1 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 1 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseScore 7.8
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackVector LOCAL
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
containers > adp > 1 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 1 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > privilegesRequired LOW
containers > adp > 1 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 1 > metrics > 1 > other > type ssvc
containers > adp > 1 > metrics > 1 > other > content > id CVE-2022-0995
containers > adp > 1 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 1 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 1 > metrics > 1 > other > content > options > 1 > Automatable no
containers > adp > 1 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 1 > metrics > 1 > other > content > version 2.0.3
containers > adp > 1 > metrics > 1 > other > content > timestamp 2026-08-26T17:44:24.162698Z
containers > adp > 1 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0995
containers > adp > 1 > references > 0 > tags > 0 government-resource
containers > adp > 1 > title CISA ADP Vulnrichment
containers > adp > 1 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 1 > providerMetadata > shortName CISA-ADP
containers > adp > 1 > providerMetadata > dateUpdated 2026-08-26T17:44:58.695Z
cveMetadata > assignerOrgId 53f830b8-0a3f-465b-8143-3b8a9948e749
cveMetadata > assignerShortName redhat
cveMetadata > cveId CVE-2022-0995
cveMetadata > datePublished 2022-03-25T18:03:08.000Z
cveMetadata > dateReserved 2022-03-16T00:00:00.000Z
cveMetadata > dateUpdated 2026-08-26T17:44:58.695Z
cveMetadata > state PUBLISHED
dataType CVE_RECORD
dataVersion 5.2