CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability
Summary
A critical out-of-bounds memory write vulnerability exists in the Linux Kernel, potentially allowing local users to escalate privileges or cause denial of service. CISA is mandating mitigations by September 9, 2026, in accordance with their risk-based patching guidance.
IFF Assessment
This vulnerability allows local users to gain privileged access, posing a direct threat to system security and integrity.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 09, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in the Linux Kernel is a significant concern as it can be exploited by local users to gain elevated privileges. Defenders should prioritize patching and applying mitigations as soon as possible, especially for internet-facing systems, adhering to CISA's risk-based patching directives.