{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3olinuxlinux_kernel5.17rc4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc3:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc4:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc5:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc6:*:*:*:*:*:*","cpe:2.3:o:linux:linux_kernel:5.17:rc7:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2022-0995"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kernel"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Linux"],"content_html":"\u003cp\u003eCVE-2022-0995 is an out-of-bounds write vulnerability within the Linux Kernel. This vulnerability exists in the implementation of the watch_queue subsystem, where improper management of memory offsets during certain pipe operations can be exploited. Because this occurs at the kernel level, a local attacker with non-privileged access to the system can trigger the memory corruption to overwrite sensitive kernel structures. This capability allows the attacker to gain elevated (root) privileges or force a kernel panic, resulting in a denial-of-service condition. Given that the Linux Kernel serves as the foundation for a vast array of enterprise, cloud, and embedded systems, the security impact is broad. Organizations are required to identify and patch vulnerable kernel versions in accordance with CISA BOD 26-04 mandates.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains initial local access to the target Linux system via a separate entry point or low-privileged account.\u003c/li\u003e\n\u003cli\u003eThe attacker interacts with the kernel's watch_queue mechanism by executing system calls specifically designed to invoke the flawed memory write operation.\u003c/li\u003e\n\u003cli\u003eThe attacker provides crafted inputs to the pipe buffer, triggering an out-of-bounds write beyond the allocated kernel memory region.\u003c/li\u003e\n\u003cli\u003eThe memory corruption is used to overwrite kernel function pointers or task structures in memory.\u003c/li\u003e\n\u003cli\u003eThe kernel executes the hijacked function pointers, redirecting the control flow to attacker-supplied shellcode or payload.\u003c/li\u003e\n\u003cli\u003eThe shellcode completes, granting the attacker root privileges on the compromised system.\u003c/li\u003e\n\u003cli\u003eThe final objective is achieved, such as establishing persistence, data exfiltration, or further lateral movement within the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise via privilege escalation, which can lead to complete loss of confidentiality, integrity, and availability of the host. The number of potentially impacted systems is extensive due to the ubiquity of the affected Linux Kernel versions. The vulnerability also poses a significant risk to cloud environments and enterprise infrastructure that rely on kernel-level security for process isolation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of Linux distributions currently running kernel versions susceptible to CVE-2022-0995. Ensure compliance with CISA BOD 26-04 for internet-facing assets and implement the required forensic triage measures if unauthorized privilege escalation is suspected. Organizations should audit all internal systems to determine if they rely on affected kernels and apply vendor-supplied security updates immediately.\u003c/p\u003e\n","date_modified":"2026-08-26T20:17:18Z","date_published":"2026-08-26T20:17:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linux-kernel-oob/","summary":"The Linux Kernel contains an out-of-bounds memory write vulnerability that enables a local attacker to achieve privilege escalation or cause a system denial of service.","title":"Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)","url":"https://feed.craftedsignal.io/briefs/2026-08-linux-kernel-oob/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:linux:linux_kernel:5.17:rc4:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}