Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2022-0995 |
| Alert Source | CISA KEV - Active Exploitation |
| CVE Year | 2022 |
| Publication Date | 2026-08-26 |
| Vendor | Linux |
| Product | Linux kernel (watch_queue subsystem) |
| CVSS Score | 7.8 (High) |
| EPSS Score | 6.3% (percentile: 93%) |
| CISA KEV | Yes - confirmed active exploitation |
| Ransomware | Not confirmed |
| Due Date | 2026-09-09 |
Vulnerability Description
Source: CISA KEV / NVD
An out-of-bounds memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. Exploiting it overwrites parts of kernel state, which a local user can turn into privileged access or a denial of service affecting the whole system.
This is a local vulnerability — the attacker must already be able to run code on the machine. In practice that makes it the second step in an attack chain: after entry through a web application, stolen SSH credentials or a service account, watch_queue is what gets them root.
Fixes have been available since 2022 in the kernels of every major distribution. This CVE appearing in the KEV catalog in 2026 shows how long unpatched kernels stay in production.
Required Actions
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 “Prioritizing Security Updates Based on Risk” guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
In practice: update the kernel to the version shipped by your distribution and reboot. A yum update without a reboot does not remove the vulnerability — the running kernel stays old.
CISA’s deadline for US federal agencies: 2026-09-09.
Who Is Affected?
The vulnerability affects systems running a Linux kernel with the watch_queue subsystem that have not received the 2022 fix.
In practice this means application and database servers, Kubernetes nodes and virtual machines that were brought up a few years ago and never rebooted — because “they work”. It is worth listing hosts by uptime: machines with uptime measured in years are the most reliable candidates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
