[KEV] CVE-2022-0995 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2022-0995 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2022-0995 is an out-of-bounds memory write vulnerability in the Linux Kernel that can be triggered by a local user.
Technical Detail
The flaw allows a local attacker to cause the Linux Kernel to write data outside the intended bounds of a memory buffer. Successful exploitation could corrupt kernel memory, resulting in denial of service or local privilege escalation to privileged system access. The supplied data does not identify a specific affected kernel component or triggering interface.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation capability is considered practical for use by threat actors rather than limited to a proof of concept. CISA has confirmed active exploitation in the wild. This vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on August 26, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize installation of vendor-supported Linux Kernel updates that remediate CVE-2022-0995, particularly on multi-user systems, servers with untrusted local access, and systems where lower-privileged accounts can execute code. Restrict local access where practical, review use of privileged containers and shared-host environments, and monitor for unexpected kernel crashes, system instability, or unusual privilege changes. CISA binding directive requirements apply to applicable federal civilian agencies: patch by the remediation date specified in CISA's KEV catalog or apply mitigations; a specific due date was not provided in the supplied data.