CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability

Summary

A critical out-of-bounds memory write vulnerability exists in the Linux Kernel, potentially allowing local users to escalate privileges or cause denial of service. CISA is mandating mitigations by September 9, 2026, in accordance with their risk-based patching guidance.

IFF Assessment

FOE

This vulnerability allows local users to gain privileged access, posing a direct threat to system security and integrity.

Severity

7.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 09, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in the Linux Kernel is a significant concern as it can be exploited by local users to gain elevated privileges. Defenders should prioritize patching and applying mitigations as soon as possible, especially for internet-facing systems, adhering to CISA's risk-based patching directives.

Read Full Story →