CVE-2022-0995Active Exploitation(fedoraproject / fedora)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch fedoraproject fedora systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

8.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-09. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fedora
  • h300e
  • h300e_firmware
  • h300s

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 12 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 11 signals
  • Peaked 7d ago at 3 mentions (2026-08-26); latest day: 1
  • 18 total mentions across 12 days

Affected systems

Products
fedorah300eh300e_firmwareh300sh300s_firmwareh410ch410c_firmwareh410sh410s_firmwareh500e

3 versions affected across 24 products

Deep dive

Activity timeline18 mentions / 12d
01223Mentions · 2026-03-11: 2Mentions · 2026-03-15: 1Mentions · 2026-03-27: 1Mentions · 2026-05-10: 1Mentions · 2026-08-26: 3Mentions · 2026-08-27: 2Mentions · 2026-08-28: 2Mentions · 2026-08-31: 1Mentions · 2026-09-01: 2Mentions · 2026-09-02: 1Mentions · 2026-09-28: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-03-11: 2PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-05-10: 1PoC Mentioned / Linked · 2026-08-26: 1Exploit Tool / Code · 2026-03-11: 1Exploit Tool / Code · 2026-03-15: 1Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-05-10: 1Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-08-28: 2Active Exploitation · 2026-08-31: 1Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-01: 2Patch / Workaround · 2026-09-02: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-27: 1Technical Details · 2026-05-10: 1Technical Details · 2026-08-26: 2Technical Details · 2026-08-27: 2Technical Details · 2026-08-28: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-02: 103-1103-1503-2705-1008-2608-2708-2808-3109-0109-0209-2810-06
Signal classification5 categories
Active Exploitation
743.8%
Exploit
425.0%
Patch
318.8%
PoC
16.3%
Disclosure
16.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-112
Exploit1PoC1
2026-03-151
Exploit1
2026-03-271
Exploit1
2026-05-101
Exploit1
2026-08-263
Active Exploitation1Disclosure1Patch1
2026-08-272
Active Exploitation1Patch1
2026-08-282
Active Exploitation2
2026-08-311
Active Exploitation1
2026-09-012
Active Exploitation1Patch1
2026-09-021
Active Exploitation1
Full discourse18 posts
  • quarkslab@quarkslab
    Exploit

    One bit flip to corrupt it all: Exploitation of an old Linux kernel vulnerability using PageJack, a modern technique to create Use After Free bugs. Here @AzazheI shows you how https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html https://t.co/jNGjuaSZyN

    Post summary

    The tweet points to a blog post that demonstrates exploitation of CVE‑2022‑0995 using the PageJack technique, providing a functional PoC, but does not mention active attacks, patches, or debunking.

    04211741099.4K
    12.2K followersView on X
  • 0xor0ne@0xor0ne
    Exploit

    CVE-2022-0995: Linux kernel OOB write in watch_queue exploited via PageJack to create a page-level UAF, overwriting struct file for LPE. Writeup by Jean Vincent (@quarkslab). https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html #infosec https://t.co/9baonX8ehV

    Post summary

    The tweet links to a detailed writeup on CVE‑2022‑0995, describing how the PageJack exploit achieves LPE via an OOB write and UAF, providing technical details and a PoC.

    410093646.2K
    92.2K followersView on X
  • 0xor0ne@0xor0ne
    Exploit

    Exploiting CVE-2022-0995 (Linux kernel OOB write in watch_queue) using the PageJack technique to create a page level UAF and overwrite struct file to gain LPE. https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html Credits (Jean Vincent) @quarkslab #infosec https://t.co/JFotEPs6Ed

    Post summary

    The post describes how to exploit CVE‑2022‑0995 using the PageJack technique, including detailed technical steps to achieve privilege escalation.

    07080434.1K
    89.1K followersView on X
  • 0xor0ne@0xor0ne

    PageJack Linux kernel exploitation technique, CVE-2022-0995 exploit example https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html Credits Jean Vincent (@quarkslab) #infosec https://t.co/yIkunL5nQf

    05061303.5K
    94.3K followersView on X
  • Linux Kernel Security@linkersec

    PageJack in Action: CVE-2022-0995 exploit Article by Jean Vincent describing how a relatively old CVE can be exploited using the PageJack exploitation technique. https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html https://t.co/JddIrSVuOt

    06037282.6K
    10.6K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    PageJack in Action: CVE-2022-0995 exploit http://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html

    Post summary

    The post announces a proof‑of‑concept for CVE‑2022‑0995 with a link to a supporting blog, but it does not detail exploit code, active attacks, patches, or deep technical specifics.

    010121.3K
    153.0K followersView on X
  • TheKnight7G@WH173H47
    Patch

    CISA has flagged CVE-2022-0995, an out-of-bounds write vulnerability in the Linux kernel. This impacts users on affected versions. Verify your kernel version and apply necessary patches.

    Post summary

    CISA has flagged CVE-2022-0995, an out-of-bounds write vulnerability in the Linux kernel, urging affected users to verify kernel versions and apply necessary patches.

    0001043
    21 followersView on X
  • NotCVE@notCVE
    Disclosure

    CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability CVSS 9.8 · EPSS 6.3% · 21 public exploits https://notcve.org/cve/CVE-2022-0995 https://t.co/eigFZIce9O

    Post summary

    The tweet announces CVE‑2022‑0995, noting its high CVSS score, type as an out‑of‑bounds write in the Linux kernel, and that 21 public exploits exist, but it does not provide a PoC link, exploit code, or patch details.

    1000026
    68 followersView on X
  • -ENOMEM@masami256
    Exploit

    PageJack in Action: CVE-2022-0995 exploit - Quarkslab's blog https://blog.quarkslab.com/pagejack-in-action-cve-2022-0995-exploit.html

    Post summary

    Quarkslab’s blog post presents a proof‑of‑concept exploit for CVE‑2022‑0995, but offers no patch, workaround, or evidence of active exploitation.

    00010139
    2.4K followersView on X
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 CRITICAL: CVE-2022-0995 - Linux Kernel out-of-bounds write vulnerability (CVSS TBD). CISA KEV listed - actively exploited. Local privilege escalation risk. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/BCowkFNNfC

    Post summary

    CVE-2022-0995 is an out‑of‑bounds write in the Linux kernel that is actively exploited per CISA KEV, and a patch is urgently required.

    0000046
    122 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Active Exploitation

    2022年に公開されたLinuxカーネルのCVE-2022-0995が、2026-08-26にKEV入りしました。watch_queueの境界外書き込みでCVSS7.8。是正期限は2026-09-09です。古いCVEが後からKEVに載る例として、掲載内容を更新しています。 https://cve.autoarticles.net/cve/CVE-2022-0995

    Post summary

    CVE-2022-0995, a Linux kernel out‑of‑bounds write flaw, was added to the KEV on 2026‑08‑26, confirming active exploitation, and a remediation deadline of 2026‑09‑09 is set.

    0000044
    556 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    2022年に直ったLinuxカーネルの権限昇格が、8月26日にKEV入りしました。期限は9月9日。影響は5.15系に集中しています。uname -r と dpkg -l のずれが「当てたが再起動していない」の正体。確認手順とKEV差分監視のjqまでまとめました。 https://blog.hashito.biz/2026/08/31/linux-cve-2022-0995-watch-queue-kev-check/

    Post summary

    A notice that CVE-2022-0995, a privilege‑escalation flaw fixed in the 5.15 Linux kernel, was added to the KEV list on August 26 with a September 9 deadline, and includes a script for monitoring the KEV update.

    0000038
    556 followersView on X
  • 凍死か@toushikaka
    Active Exploitation

    【朝のセキュリティ】脅威動向 (2026-08-31) 週末の最大の焦点は印刷管理ソフトPaperCutの緊急パッチ再リリース。1回目のパッチに回避策が見つかり、悪用は継続中。該当サーバを使う組織は至急確認を。 🚨 脆弱性・パッチ 🔴 PaperCut NG/MF → 2件の脆弱性(CVE-2026-82078 / CVSS 9.4、CVE-2026-81578 / CVSS 8.8)が実際に悪用中。組み合わせると認証なしで遠隔からサーバを乗っ取れる。最初の緊急パッチに回避手法が見つかり、8/28に2回目の緊急パッチ(Emergency Patch Release 2)が公開された。1回目を適用済みでも再適用が必要。 🟡 CISA KEV追加 → 米当局CISAがKEV(悪用が確認された脆弱性の登録簿)に6件を追加。Citrix NetScaler、Microsoft SQL Server(CVE-2019-1068)、Linuxカーネル(CVE-2022-0995)など。2015〜2019年の古い脆弱性も含まれ、中国系グループが教育・メディア・技術業界のWebサーバを狙う攻撃に使用中との報告。パッチ未適用の古いサーバが標的になっている。 🕵️ 攻撃・インシデント ・Chrome/Edgeの不正拡張機能 → 公式ストアで配布された19本の拡張機能に、暗号資産ウォレットの情報を盗み送金先をすり替える機能。約8万ユーザーが導入。最初は無害版を配布し、後から悪性版に更新する手口のため、導入済み拡張機能の棚卸しを。 ・英マンチェスター空港グループ → 恐喝グループFulcrumSecが約86GBのデータ窃取を主張。駐車場・ラウンジ予約や空港Wi-Fi登録の顧客情報が対象。報道ベースでは、公表内容より詳細な予約・渡航情報が含まれる模様(調査中)。 ・Anthropic(Claude) → PCに感染したインフォスティーラー(情報窃取マルウェア)がブラウザのログイン済みセッションを盗み、他人のアカウントを勝手に使う被害を同社が警告。パスワードや2段階認証を経ずに乗っ取れる点が厄介で、Claude固有の欠陥ではなく他のWebサービスでも同じ手口が成立する。 #サイバーセキュリティ #脆弱性 #セキュリティ

    Post summary

    PaperCut NG/MF vulnerabilities CVE-2026-82078 and CVE-2026-81578 are actively exploited in the wild, prompting emergency patches and a second patch release, while CISA KEV listings confirm widespread use of older CVEs in ongoing attacks.

    00000422
    146 followersView on X
  • Soy Nube Negra@Soy_Nube_Negra
    Active Exploitation

    🛡️ CISA KEV — seis fallas nuevas, de NetScaler a Linux kernel, con fecha límite 29 de agosto Impacto: CVE-2019-1068 en SQL Server, CVE-2026-8452 en NetScaler, CVE-2022-0995 en Linux kernel y tres de Red Hat más CVE-2021-23758 afectan appliances de borde y servidores web. Estado: explotadas por el grupo chino UAT-10147 según Talos y con 36 intentos en 12 días desde 12 IPs. Plazo federal: 29 de agosto para NetScaler/SQL Server y 9 de septiembre para el resto. Acción hoy: 1. Parchear NetScaler, SQL Server e internet-facing Linux primero. 2. Revisar versiones sin soporte que nunca recibirán fix. 3. Priorizar lo expuesto antes que lo interno. Un KEV que mezcla vulnerabilidades de 2015 con 2026 recuerda que la edad no baja el riesgo. Sigue a @Soy_Nube_Negra si te sirve este tipo de análisis. https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html

    Post summary

    The post reports that six newly disclosed vulnerabilities are actively being exploited by the UAT‑10147 group, lists the CVEs and affected systems, and recommends immediate patching.

    0000071
    1.9K followersView on X
  • Nicolas Coolman@NicolasCoolman
    Active Exploitation

    📢Alerte CISA : Exploitation Active de la vulnérabilité CVE-2022-0995 dans le Kernel Linux qui permet une élévation de privilèges locale. #zoneantimalware https://zoneantimalware.com/cisa-linux-kernel-alerte/

    Post summary

    The announcement highlights that CVE-2022-0995 is actively exploited on the Linux kernel, presenting a local privilege escalation vector, without providing PoC, exploitation tools, or patch details.

    0000051
    88 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性6件をカタログに追加 CISA Adds Six Known Exploited Vulnerabilities to Catalog #CISA (Aug 26) CVE-2015-3246 Red Hat Libuserの競合状態の脆弱性 CVE-2015-5287 Red Hat自動バグ報告ツールにおける権限昇格の脆弱性 CVE-2019-1068 Microsoft SQL Serverのリモートコード実行の脆弱性 CVE-2021-23758 http://Ajax.NET Professionalにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2022-0995 Linuxカーネルの境界外書き込みの脆弱性 CVE-2026-8452 Citrix NetScaler ADCおよびNetScaler Gatewayにおけるメモリバッファの範囲内での操作の不適切な制限の脆弱性 https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has updated its catalog to list six CVEs that are known to be actively exploited in the wild; the note provides technical details but no PoC, exploit code, or patch information.

    00000304
    4.9K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2022-0995 - Linux Kernel out-of-bounds write flaw (CISA KEV). Local attackers can gain privileged access or cause DoS. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/VgREGSksF9

    Post summary

    The tweet highlights a critical Linux Kernel out-of-bounds write flaw (CVE-2022-0995), urging immediate patching while providing minimal technical details and no exploitation evidence.

    0000043
    115 followersView on X
  • Kaotick Jay@kaotickjay
    Active Exploitation

    CISA adds 6 active exploits to KEV • CVE-2015-3246 — Red Hat Libuser • CVE-2015-5287 — Red Hat ABRT • CVE-2019-1068 — Microsoft SQL Server • CVE-2021-23758 — https://Ajax.NET Professional • CVE-2022-0995 — Linux Kernel • CVE-2026-8452 — Citrix NetScaler ADC/Gateway

    Post summary

    CISA’s recent update announces six CVEs that are actively exploited in the wild, as part of the KEV list.

    0000061
    13 followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora35--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.17--
OSlinuxlinux_kernel5.17--
OSlinuxlinux_kernel5.17--
OSlinuxlinux_kernel5.17--
OSlinuxlinux_kernel5.17--
OSlinuxlinux_kernel5.17--
OSlinuxlinux_kernel5.17--
HWnetapph300e---
OSnetapph300e_firmware---
HWnetapph300s---
OSnetapph300s_firmware---
HWnetapph410c---
OSnetapph410c_firmware---
HWnetapph410s---
OSnetapph410s_firmware---
HWnetapph500e---
OSnetapph500e_firmware---
HWnetapph500s---
OSnetapph500s_firmware---
HWnetapph610c---
OSnetapph610c_firmware---
HWnetapph610s---
OSnetapph610s_firmware---
HWnetapph615c---
OSnetapph615c_firmware---
HWnetapph700e---
OSnetapph700e_firmware---
HWnetapph700s---
OSnetapph700s_firmware---

Explore more