CVE-2022-0995

Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 25 Mar 2022, 18:03
Last modified:02 Aug 2024, 23:47

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
22.21% HIGH
22% probability +1.71%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

25 Mar 2022, 18:03
Published
Vulnerability first disclosed
02 Aug 2024, 23:47
Last Modified
Vulnerability information updated

Description

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 22.21% Percentile: 96%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • fedoraprojectfedora

    35

  • linuxlinux_kernel

    ≥ 5.8, < 5.10.106 | ≥ 5.11, < 5.15.29 | ≥ 5.16, < 5.16.5 | 5.17:rc1 | 5.17:rc2 | 5.17:rc3 | 5.17:rc4 | 5.17:rc5 | 5.17:rc6 | 5.17:rc7

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph610c_firmware

    na

  • netapph610s_firmware

    na

  • netapph615c_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

References (5)