Skip to content
Security Alerts

CVE-2022-0995: Out-of-Bounds Write in Linux Kernel watch_queue

An out-of-bounds memory write in the watch_queue event notification subsystem can overwrite parts of kernel state, leading to privilege escalation or denial of service...

Summary

ParameterValue
CVE IDCVE-2022-0995
Alert SourceCISA KEV - Active Exploitation
CVE Year2022
Publication Date2026-08-26
VendorLinux
ProductLinux kernel (watch_queue subsystem)
CVSS Score7.8 (High)
EPSS Score6.3% (percentile: 93%)
CISA KEVYes - confirmed active exploitation
RansomwareNot confirmed
Due Date2026-09-09

Vulnerability Description

Source: CISA KEV / NVD

An out-of-bounds memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. Exploiting it overwrites parts of kernel state, which a local user can turn into privileged access or a denial of service affecting the whole system.

This is a local vulnerability — the attacker must already be able to run code on the machine. In practice that makes it the second step in an attack chain: after entry through a web application, stolen SSH credentials or a service account, watch_queue is what gets them root.

Fixes have been available since 2022 in the kernels of every major distribution. This CVE appearing in the KEV catalog in 2026 shows how long unpatched kernels stay in production.

Required Actions

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 “Prioritizing Security Updates Based on Risk” guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In practice: update the kernel to the version shipped by your distribution and reboot. A yum update without a reboot does not remove the vulnerability — the running kernel stays old.

CISA’s deadline for US federal agencies: 2026-09-09.

Who Is Affected?

The vulnerability affects systems running a Linux kernel with the watch_queue subsystem that have not received the 2022 fix.

In practice this means application and database servers, Kubernetes nodes and virtual machines that were brought up a few years ago and never rebooted — because “they work”. It is worth listing hosts by uptime: machines with uptime measured in years are the most reliable candidates.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist