CVE-2022-0995 carries a CVSS 3.1 base score of 7.8 against the Linux kernel. NVD classifies it as CWE-787 (Out-of-Bounds Write). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 26, 2026 — confirming exploitation directly through CISA’s own listing process, more than four years after this vulnerability was originally disclosed in March 2022.
Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.
What the flaw is
NVD’s description states an out-of-bounds memory write flaw exists in the Linux kernel’s watch_queue event notification subsystem, which can overwrite parts of the kernel’s internal state, potentially allowing a local user to gain privileged access or cause a denial of service. NVD’s CVSS vector marks this local (AV:L) and requiring low privileges (PR:L), consistent with a local privilege-escalation profile rather than a remotely reachable flaw. The upstream kernel fix commit, linked from NVD’s record, is the authoritative technical source for the specific correction.
Evidence and confidence
- High confidence — exploitation status, sourced directly from CISA KEV, which our evidence model treats as an authoritative single source for this specific field.
- Medium confidence — the CVSS 7.8 score, the vector (
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and the CWE-787 classification, which trace to NVD alone in our current ingestion, corroborated by the upstream kernel fix commit NVD links. - Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.09518, a 95.2nd percentile score as of our ingestion — among the highest in our recent KEV coverage.
No field is in conflict between our two sources. Our data carries no single fixed-version field; the upstream kernel commit NVD links identifies the corrected code.
Why this matters
A 2022-disclosed kernel vulnerability appearing on CISA’s KEV catalog in 2026 typically reflects newly observed exploitation of systems running kernel versions that were never updated to include the fix, a pattern this publication has covered before with other long-unpatched software, including two other CVEs in this cycle’s coverage. Kernel-level local privilege-escalation flaws are especially valuable to attackers who have already gained limited local code execution through some other means, since they provide a path to full root access or a container/sandbox escape.
The near-maximal EPSS percentile (95.2nd) combined with CISA’s direct confirmation of exploitation indicates active use of this flaw today, not a dormant historical entry — any organization running kernel versions predating the fix should prioritize identifying and patching affected systems.
Frequently Asked Questions
What is CVE-2022-0995? A CVSS 7.8 out-of-bounds write vulnerability (CWE-787) in the Linux kernel’s watch_queue event notification subsystem, allowing a local user to overwrite kernel state and potentially gain privileged access or cause a denial of service.
Is CVE-2022-0995 being actively exploited? Yes, per CISA’s own Known Exploited Vulnerabilities catalog, which added this CVE on August 26, 2026.
Why is a 2022 CVE showing up in a 2026 KEV feed? CISA added it to its Known Exploited Vulnerabilities catalog in August 2026 — more than four years after initial disclosure — which typically reflects newly observed exploitation of systems running unpatched kernel versions, not a new vulnerability.
Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.
Which kernel versions fix this? Our source data carries no single fixed-version field. Consult the upstream kernel fix commit linked from NVD’s record for the specific version that includes the fix.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2022-0995 and the linked upstream Linux kernel fix commit. Exploitation status and the August 26, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.