← Vulnerability feed

Vulnerability record · CVE-2022-0995 · published 25 March 2022

CVE-2022-0995: Linux kernel watch_queue out-of-bounds write

Linux · Linux Kernel

The Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user can leverage this to escalate privileges or crash the system, making it a serious post-access escalation flaw on affected kernels.

7.8 CVSS 3.1 High CISA KEV since 26 Aug 2026 EPSS 8.8% · top 5.0% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 7.2
8.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
13Affected product versions listed by NVD
11References, 4 tagged exploit
27 Aug 2026Last modified by NVD

Description

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityLocal privilege escalation with public exploit code and CISA KEV listing, though it requires local access and no ransomware use is documented.

What it is

The Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user can leverage this to escalate privileges or crash the system, making it a serious post-access escalation flaw on affected kernels.

Impact

An attacker with local access can corrupt kernel memory, potentially gaining privileged (root) access or causing a denial of service.

Attack surface

Reached locally via the watch_queue subsystem; the CVSS vector AV:L/PR:L/UI:N indicates a local attacker with low privileges and no user interaction required. No remote or network vector is described.

Exploitation

CISA added this to the KEV catalog (due 2026-09-09) and public exploit code is referenced on Packet Storm, indicating known exploitation; EPSS 30-day probability is about 9.5% (95th percentile). No ransomware campaign use is documented.

What to do

  • Apply the upstream Linux kernel patch (commit 93ce93587d36493f2f86921fa79921b3cba63fbb) or the vendor kernel update for your distribution.
  • For Fedora and NetApp products listed, apply the respective vendor advisories (Red Hat Bugzilla 2063786, NetApp ntap-20220429-0001).
  • Restrict local shell and unprivileged account access on affected hosts to reduce the local attack surface.
  • Follow CISA BOD 26-04 guidance and the KEV required action, discontinuing use of the product if no mitigation is available.

Detection

  • Monitor for kernel crash or oops events tied to watch_queue and unexpected privilege escalation on affected hosts.
  • Audit local user activity and process execution for known public exploit patterns against watch_queue.
  • Track kernel versions against the patched commit to identify unpatched systems.
  • Alert on anomalous root-level process creation from low-privileged local accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Linux Kernel Out-of-Bounds Write Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 9 September 2026.

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0995 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-54085AMI MegaRAC SPx BMC authentication bypass via Redfish Host InterfaceAMI's SPx BMC implementation contains an authentication bypass reachable remotely through the Redfish Host Interface, classified as CWE-290 (authenti…KEVEPSS 61%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed

Source: NIST National Vulnerability Database (record CVE-2022-0995), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.