CVE-2022-0995: High severity Linux Linux kernel vulnerability
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watchqueue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
Other sources
The watchqueue event notification subsystem in the kernel has a couple of out of bounds writes that can be triggered by any user. These can be used to overwrite parts of the kernel state, potentially allowing the user to gain privileged access to or panic the system.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0995?
The severity of CVE-2022-0995 is high with a CVSS score of 7.8.
How does CVE-2022-0995 affect the Linux kernel?
CVE-2022-0995 affects the Linux kernel's watch_queue event notification subsystem, allowing for an out-of-bounds (OOB) memory write.
What is the potential impact of CVE-2022-0995?
The potential impact of CVE-2022-0995 is gaining privileged access or causing a denial of service on the system.
Which versions of the Linux kernel are affected by CVE-2022-0995?
The Linux kernel versions 5.8-5.10.106, 5.11-5.15.29, and 5.16-5.16.5 are affected by CVE-2022-0995.
Is there a fix available for CVE-2022-0995?
The fix for CVE-2022-0995 is available in kernel version 5.17 and above.