CVE-2022-0995
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A bug in Linux kernel's watch_queue system allows local users to write data beyond memory boundaries, potentially gaining admin access or crashing the system.
Out-of-bounds memory write vulnerability in the kernel's watch_queue event notification subsystem (CWE-787) allows local authenticated or unprivileged users to overwrite kernel memory structures, potentially leading to privilege escalation or denial of service. Requires local system access as a precondition.