EUVD Vulnerability Catalog
Actively Exploited (KEV)
EUVD-2022-15988
Severity: HIGH
Base Score: 7.8
CVSS Version: 3.1
Vulnerability Description
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Local
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): Low
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
n/a
References & Advisory Links
- https://bugzilla.redhat.com/show_bug.cgi?id=2063786
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb
- http://packetstormsecurity.com/files/166770/Linux-watch_queue-Filter-Out-Of-Bounds-Write.html
- http://packetstormsecurity.com/files/166815/Watch-Queue-Out-Of-Bounds-Write.html
- https://security.netapp.com/advisory/ntap-20220429-0001/
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
redhat
EPSS Probability
6.34
Known Aliases
GHSA-q5p3-3mpm-hppr
CVE-2022-0995
Published On
2022-03-25
Last Updated
2026-08-26
Exploited Since
2026-08-26