Knox CVE Database
/
CVE-2022-0995
High
7.8

CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

Added to the CISA KEV catalog:
August 26, 2026

Overview

The Linux kernel's watch_queue event notification subsystem fails to properly bounds-check a user-supplied filter parameter, allowing an out-of-bounds write into kernel memory. A local unprivileged user on an affected system can corrupt kernel state to escalate privileges to root or trigger a kernel crash. Kernel versions from 5.8 through the 5.17 development series are affected, with fixed boundaries at 5.10.106, 5.15.29, and 5.16.5 for their respective stable lines.

Vulnerability details

Affected vendor
Linux
Affected product
Kernel
Weakness type (CWE)
CWE-787

The flaw is an out-of-bounds write (CWE-787) in the kernel's watch_queue subsystem, specifically in the filter limit check. When a local process configures a watch_queue filter via a syscall, the kernel does not adequately validate the supplied filter parameter before using it to write into kernel memory. A value outside the expected range causes the write to land beyond the allocated buffer, overwriting adjacent kernel state. The commit fixing this issue is described as "watch_queue: Fix filter limit check," confirming the bounds validation was absent or incorrect.


An attacker with a local, non-root account submits a crafted filter configuration to the watch_queue subsystem. Because the kernel writes attacker-influenced data past the buffer boundary, the attacker can corrupt kernel structures in a controlled manner and escalate to root privileges. Alternatively, the corruption can cause a kernel panic, producing a denial of service. The watch_queue subsystem must be accessible to the local user, and the running kernel must fall within the affected version range. No network access or interaction from another user is required.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for unexpected privilege transitions on hosts running affected kernel versions: a process that begins execution as an unprivileged user and later performs actions requiring root (writing to /etc/passwd, loading kernel modules, or binding privileged ports) without a corresponding su or sudo event is a strong indicator of local privilege escalation.
  • Kernel oops or panic messages referencing watch_queue or pipe ring memory regions in /var/log/kern.log or the systemd journal (journalctl -k) may indicate exploitation attempts that did not fully succeed, particularly on systems where no legitimate application uses the watch_queue API.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 9, 2026

Additional hardening

  • Update the Linux kernel to 5.10.106 or later for the 5.10 stable line, 5.15.29 or later for the 5.15 stable line, or 5.16.5 or later for the 5.16 stable line. Consult the vendor advisory in References for other release lines.
  • Restrict local user access on multi-tenant or shared systems: reduce the number of accounts with interactive shell access, apply the principle of least privilege, and audit group memberships that grant access to kernel interfaces.
  • Apply seccomp profiles or LSM policies (SELinux, AppArmor) to confine untrusted processes and restrict their ability to invoke watch_queue-related syscalls, reducing the attack surface even on unpatched kernels.
  • Audit systems for kernel versions in the affected range using package manager queries or uname -r output, and prioritize patching on hosts where local access is granted to untrusted or shared users.

Key dates

Published (NVD)
March 25, 2022
Added to CISA KEV
August 26, 2026
Remediation deadline
September 9, 2026
Last updated
August 27, 2026

References

Frequently asked questions

Does CVE-2022-0995 affect my FedRAMP authorization?

If Linux Kernel runs inside your authorization boundary, yes, CVE-2022-0995 affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 9, 2026. For any FedRAMP-authorized service, an unpatched KEV within the boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it as a deficiency.

How does Knox help me handle CVE-2022-0995?

Knox does not patch Linux Kernel on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2022-0995 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to support your next assessment. The fix belongs to your team; maintaining a defensible compliance posture while you apply it is not something you have to manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a vulnerability like CVE-2022-0995, that means exposure surfaces during routine monitoring rather than only when an assessor flags it at review time, giving your team more time to act before a deadline becomes a finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2022-0995 isn't remediated by September 9, 2026?

Missing the September 9, 2026 deadline turns CVE-2022-0995 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing intact and preserves the agency relationship you depend on to close and retain federal contracts.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting