CVE-2022-0995
KEVHIGH 7.8EPSS 9.5%
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 9.52% chance of exploitation in the next 30 days, 95th percentile
- CISA KEV
- added 2026-08-26
- Published
- 2022-03-25
- Updated
- 2026-08-27
Proof-of-concept exploits (6)
- http://packetstormsecurity.com/files/166770/Linux-watch_queue-Filter-Out-Of-Bounds-Write.…
- http://packetstormsecurity.com/files/166815/Watch-Queue-Out-Of-Bounds-Write.html
- 1nzag/CVE-2022-09951★ · 2024-01-03
- A1b2rt/cve-2022-09950★ · 2025-06-25
- AndreevSemen/CVE-2022-09951★ · 2023-03-10
- Bonfee/CVE-2022-0995497★ · 2022-03-27