Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
The Linux kernel's watch_queue event notification subsystem fails to properly bounds-check a user-supplied filter parameter, allowing an out-of-bounds write into kernel memory. A local unprivileged user on an affected system can corrupt kernel state to escalate privileges to root or trigger a kernel crash. Kernel versions from 5.8 through the 5.17 development series are affected, with fixed boundaries at 5.10.106, 5.15.29, and 5.16.5 for their respective stable lines.
The flaw is an out-of-bounds write (CWE-787) in the kernel's watch_queue subsystem, specifically in the filter limit check. When a local process configures a watch_queue filter via a syscall, the kernel does not adequately validate the supplied filter parameter before using it to write into kernel memory. A value outside the expected range causes the write to land beyond the allocated buffer, overwriting adjacent kernel state. The commit fixing this issue is described as "watch_queue: Fix filter limit check," confirming the bounds validation was absent or incorrect.
An attacker with a local, non-root account submits a crafted filter configuration to the watch_queue subsystem. Because the kernel writes attacker-influenced data past the buffer boundary, the attacker can corrupt kernel structures in a controlled manner and escalate to root privileges. Alternatively, the corruption can cause a kernel panic, producing a denial of service. The watch_queue subsystem must be accessible to the local user, and the running kernel must fall within the affected version range. No network access or interaction from another user is required.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Linux Kernel runs inside your authorization boundary, yes, CVE-2022-0995 affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 9, 2026. For any FedRAMP-authorized service, an unpatched KEV within the boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it as a deficiency.
Knox does not patch Linux Kernel on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2022-0995 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to support your next assessment. The fix belongs to your team; maintaining a defensible compliance posture while you apply it is not something you have to manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a vulnerability like CVE-2022-0995, that means exposure surfaces during routine monitoring rather than only when an assessor flags it at review time, giving your team more time to act before a deadline becomes a finding.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
Missing the September 9, 2026 deadline turns CVE-2022-0995 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing intact and preserves the agency relationship you depend on to close and retain federal contracts.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









