← Back to overview

CVE-2022-0995 is an out-of-bounds memory write vulnerability in the Linux Kernel. It allows a local user to gain elevated privileges or cause a denial of service on affected systems. The vulnerability is tracked by CISA and listed under BOD 26-04, which prioritizes security updates based on risk. It affects an open-source component that may be used across a wide range of products and distributions. A patch has been committed to the mainline Linux kernel repository by Linus Torvalds. CISA has provided forensic triage requirements and implementation guidance for organizations needing to remediate. The vulnerability is rated High severity, underscoring the importance of timely patching for Linux-based environments.

Affected products

  • Linux Kernel

Related CVE's

  • CVE-2022-0995

Categories

  • Operating Systems
  • Zero-Day Vulnerabilities