All incidents

CISA adds Linux kernel flaw CVE-2022-0995 to KEV catalogue

vulnerabilityopenAug 26, 2026 — Aug 27, 2026

ON 26 August 2026 the Cybersecurity and Infrastructure Security Agency added CVE‑2022‑0995 to its Known Exploited Vulnerabilities catalogue. The flaw resides in the Linux kernel and can allow a local user to gain privileged access or crash the system. CISA’s move signals that the issue is being actively exploited in the wild.

CVE‑2022‑0995 scores 7.8 on the CVSS scale, rating it as high severity. It is an out‑of‑bounds write vulnerability in the kernel’s memory handling code. An attacker with local access can craft a malicious input that writes beyond allocated memory, which may lead to arbitrary code execution with kernel privileges or a denial‑of‑service condition.

The vulnerability affects Linux kernel releases that lack the corrective patch released earlier this year. While the exact version numbers depend on the distribution, any system running an unpatched kernel is potentially exposed. Vendors have issued updates that address the out‑of‑bounds write.

CISA’s inclusion of the flaw in the KEV catalogue indicates that it has been observed in exploitation attempts, although no specific threat actors have been linked to the issue. The vulnerability requires local access, which limits its remote impact but still poses a significant risk for shared or multi‑tenant environments. This aligns with the guidance set out in Binding Operational Directive 26‑04.

Defenders should prioritize applying the latest kernel patches supplied by their Linux distribution. Following CISA’s advice, systems should be reviewed for compliance with BOD 26‑04 and any mitigations should be verified. Where immediate patching is not possible, restricting local user privileges and monitoring for abnormal kernel behaviour can help reduce risk.

Organisations are encouraged to monitor the KEV catalogue for further updates and to report any unlisted vulnerabilities they encounter. Keeping patch management processes up to date remains the most effective defence against kernel‑level flaws like CVE‑2022‑0995.

Intelligence briefing updated Aug 27, 2026

CVE-2022-0995 7.8 KEV
Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline