Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Linux Kernel Out-of-Bounds Write (CVE-2022-0995)

Catalog analysis: CISA added this entry on August 26, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.

What the vulnerability is

CVE-2022-0995 is an out-of-bounds memory write vulnerability (CWE-787) residing within the Linux Kernel. This flaw allows a local user to perform unauthorized memory writes, which could result in the attacker gaining privileged access to the system or triggering a denial of service (DoS).

Exposure and applicability

This vulnerability affects systems running susceptible versions of the Linux Kernel. Because the kernel is an open-source component integrated into numerous distributions and proprietary implementations, exposure extends across various hardware architectures and operating system flavors utilizing the affected code. The primary attack vector is local; an actor must already have a foothold on the system to exploit the memory write flaw for privilege escalation.

Remediation priorities

Our analysis suggests prioritizing remediation based on the asset’s role in the environment and its level of accessibility to non-privileged users.

  1. Immediate Patching: Systems with high numbers of local users or those hosting multi-tenant workloads should be prioritized for updates. Defenders should apply vendor-supplied mitigations that incorporate the fix identified in git.kernel.org commit 93ce93587d36493f2f86921fa79921b3cba63fbb.
  2. Asset Identification: Infrastructure owners must identify all instances of the Linux Kernel across physical, virtual, and cloud environments to ensure no legacy or shadow systems remain unpatched.
  3. Privilege Review: While not a direct fix for the memory flaw, reducing the number of users with local shell access can reduce the available attack surface until patching is verified.

How to validate remediation

Verification must move beyond simple version string checks, as kernel versions vary by distribution and backported fixes may be present in older version numbers.

  • Commit Verification: The most reliable method of validation is confirming that the specific fix (commit 93ce93587d36493f2f86921fa79921b3cba63fbb) has been integrated into the running kernel build.
  • Configuration Audit: For organizations subject to federal mandates, validation should include evidence of compliance with BOD 26-04 and associated forensics triage requirements.

Confirmation that a patch was deployed does not equate to confirmation that the vulnerability is mitigated; defenders should verify the active kernel in memory matches the patched version on disk.

Limits and open questions

There are remaining uncertainties regarding the specific exploitability of this flaw across different kernel configurations. While it is known that local privilege escalation is possible, the exact conditions required to trigger the out-of-bounds write may vary by environment. Additionally, while CISA has added this to the Known Exploited Vulnerabilities catalog, the source does not specify if it is currently being utilized in known ransomware campaigns.

Source and editorial note

CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability · Source date: August 26, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment