CISA KEV · catalog date Aug 26, 2026 · first observed Aug 27, 2026
Evidence dossier
CVE-2022-0995
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem.
Exploited in the wild (CISA KEV since Aug 26, 2026). NVD reports CVSS 3.1 7.8. EPSS estimates 9.5% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
- State
- PUBLISHED
- Published
- Mar 25, 2022
- Updated
- Aug 2, 2024
- Evidence coverage
- 85%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAredhatOriginal evidence ↗
Record text: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
Inspect raw assertion
- Field
container- Value
- An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Out-of-Bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Out-of-Bounds Write Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 9.52% probability · 95.08th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.095180000000; percentile 0.950770000000
FIRST EPSS · score date Aug 27, 2026 · 95.1th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Aug 26, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
Inspect raw assertion
- Field
container- Value
- An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
Linux Kernel Out-of-Bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Out-of-Bounds Write Vulnerability
9.52% probability · 95.08th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.095180000000; percentile 0.950770000000
Applicability
Cited product scope
Grouped from 24 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
25 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "kernel 5.17 rc8"}]product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertion
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80e516c0-98a4-4ade-b69f-66a772e2baaa
product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exactInspect raw assertions
cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e6e34b23-78b4-4516-9bd8-61b33f4ac49a
cpe:2.3:o:linux:linux_kernel:5.17:rc5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
efa3917c-c322-4d92-912d-ece45b2e7416
cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c030fa3d-03f4-4fb9-9dbf-d08e5cac51aa
cpe:2.3:o:linux:linux_kernel:5.17:rc7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f635f96-fa0a-4769-ade8-232b3ac9116d
cpe:2.3:o:linux:linux_kernel:5.17:rc4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2d2677c-5389-4ae9-869d-0f881e80d923
cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7bd5f8d9-54fa-4cb0-b4f0-cb0471fddb2d
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 5.11; through excluding 5.15.29
- Match ID
15dc6588-b28f-4637-9a1e-3753b34a40cf
cpe:2.3:o:linux:linux_kernel:5.17:rc6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bed18363-5abc-4639-8bba-68e771e5bb3f
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 5.16; through excluding 5.16.5
- Match ID
1ad9e77e-b27e-450c-8fd8-b64ec5fb002d
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 5.8; through excluding 5.10.106
- Match ID
ffaca37d-d2ea-44a7-8ed6-e58ee2222afe
product-5e8aff139fa83ae85f478f3473c05dbdb594f6f806121b02c3f419f2a2da62d5Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7afc73ce-abb9-42d3-9a71-3f5bc5381e0e
product-fc149af9032ace9a010e9f89149c81bc45faeba303217af053928b26be955f3dLinked exactInspect raw assertion
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
108a2215-50fb-4074-94cf-c130fa14566d
product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9c8c20-42eb-4ab5-bd97-212deb070c43
product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exactInspect raw assertion
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6770b6c3-732e-4e22-bf1c-2d2fd610061c
product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cddf61b7-ec5c-467c-b710-b89f502cd04f
product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
234defe0-5ce5-4b0a-96b8-5d227cb8ed31
product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8497a4c9-8474-4a62-8331-3fe862ed4098
product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0b4ad8a-f172-4558-aec6-ff424ba2d912
product-e1a5a15eac66519d4e1187be3639955761cab5eb471d3f739edd906febb8b689Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
803bc414-b250-4e3a-a478-a3881340d6b8
product-f6f14489b90770f5fcf332bfe05780026ac83b5a028570dad28517167b27d8b7Linked exactInspect raw assertion
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32f0b6c0-f930-480d-962b-3f4efdcc13c7
product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e63d8b0f-006e-4801-bf9d-1c001bbfb4f9
product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7fff7106-ed78-49ba-9ec5-b889e3685d53
product-ed4a7e11b44c9039dfd403943a9e472ccedc79d9e8541224473f43934c8070fcLinked exactInspect raw assertion
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f3d9b255-c1af-42d1-bf9b-13642fbdc080
product-6b9f0b72c1309966cd256d7a215b9cab906dcc64be1cb9f934c338c91e098620Linked exactInspect raw assertion
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
89612649-bacf-4fac-9ba4-324724fd93a6
product-3957199dfb29d702382dde1506ec753a2e995f2a797bfa3f56758eba63ced183Linked exactInspect raw assertion
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f63a3fa7-aaed-4a9d-9fde-6195302da0f6
product-ce5a951956802b54eda64165939e5e2c5df7ce5a73bad036b8ea9a7eb7fd5eedLinked exactInspect raw assertion
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fd7cfe0e-9d1e-4495-b302-89c3096fc0df
product-52af2574ac0f9c1b487cc0741541f20dd00f4e53cfea1d070b592189144330d5Linked exactInspect raw assertion
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7296a1f2-d315-4fd5-8a73-65c480c855be
product-ca781182502f30abba72205d9867148c0b7d38157be8f19331a6471eb3d41e5eLinked exactInspect raw assertion
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5921a877-18bf-43fe-915c-d226e140acfc
product-0b15bdf94d171d9ff04dd6ff3be42b5de90d27fbebaa46da1a0a64b95b2b58c1Linked exactInspect raw assertion
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
736aeae9-782b-4f71-9893-ded53367e102
product-a9b8857994572d5d62ec3361bb9cf6d6b9ed2a9b747716f6a517489acf47bb51Linked exactInspect raw assertion
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0feb3337-bfde-462a-908b-176f92053cec
product-fcd38a3bd0a96c349925cecfd0d22ecf9836f21d88da8f545d6938975aa84275Linked exactInspect raw assertion
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b06f4839-d16a-4a61-9bb5-55b13f41e47f
product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6dLinked exactInspect raw assertion
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56409cec-5a1e-4450-aa42-641e459cc2af
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 2 source-reported links
Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
30648ebe-f452-4fd9-8ea5-9ca3020c0edeCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Nvd cpe vulnerable target
- Assertions
- 22
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0117e97a-fb7c-4a9c-87b3-9b42779ddff30e6c32f2-f79b-4468-a6e5-c111a238f847221c4f75-4e87-4851-aa26-4276011ace99287552e0-fc6b-4284-b386-af59caaf25c828d63832-d1a1-47d9-902c-867eb1a30f7a5d7c8156-cf61-4e00-9d8f-7c9a03dd4ba06b712085-44e8-46c9-b423-da86295a70157731ad6a-acbd-4ad4-85ff-1e3b84f0132d780d1211-365f-4019-9afc-e48fcb72a8687df38a69-a64a-4336-9ab9-a0d56fecb63d7f29e412-ece2-49ed-93d2-4dd6379da5bc82fca27b-49f5-4603-be87-35b9b5aa631792745415-6e57-477a-a371-e2d57333aba19f80fa1d-ad0f-41e8-a60f-603facfafc5ab7ce7287-4e72-4b69-84ce-b99bfe3f9373cbc003b0-48f3-4362-b104-d79c113c8154d23c2ecf-7476-4476-a681-a4b883ca91c1d66f58a1-a815-4e25-9ebe-18e718842367e340b0a7-4a17-42c9-9555-bf95884c2b54f18c67cf-d2b8-4e5b-821b-f0411f68e866f1dbb237-3920-4850-93f5-e4e48eeb87c7ff6770a9-05aa-472e-a3d6-01f0b1f041e5Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.