← back
CVE-2022-0995highunder attackCWE-787

CVE-2022-0995

86Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 8.8%
from disclosure to weapon1 days
Published on NVDMar 25
1st PoC+1d
metasploitMar 14
CISA KEV+1615d
exploitation probability
8.8%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
5 products (222 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 7 · Red Hat Virtualization 4 · Red Hat Enterprise Linux 6
Action required by CISAfederal deadline: 2026-09-09

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

A bug in Linux kernel's watch_queue system allows local users to write data beyond memory boundaries, potentially gaining admin access or crashing the system.

Technical detail

Out-of-bounds memory write vulnerability in the kernel's watch_queue event notification subsystem (CWE-787) allows local authenticated or unprivileged users to overwrite kernel memory structures, potentially leading to privilege escalation or denial of service. Requires local system access as a precondition.

Summary generated and translated by AI from the official description.
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · kernel
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.