Build. Connect. Analyse.

The Security team has detected a vulnerability with a high severity. This document will provide a brief description of the vulnerability, a list of affected operating systems and/or software.   

Overview of the Vulnerability:   

CVE-2022-0995 is an out-of-bounds memory write vulnerability in the Linux kernel’s watch_queue event notification subsystem. When a watch queue filter is configured, the watch_queue_set_filter() function validated the filter type supplied by user space against the size of the filter bitmap rather than against the number of watch types the kernel supports. This allows an attacker to specify a filter type beyond the bounds of the allocated bitmap, causing the kernel to set a bit outside of the heap allocation. 

The flaw can be triggered by any local, unprivileged user, as a watch queue can be created on an ordinary pipe and does not require elevated capabilities or the use of user namespaces. By grooming the kernel heap so that a chosen object sits adjacent to the filter allocation, an attacker can corrupt kernel state and escalate their privileges to root, or cause a denial of service by crashing the system. Public proof-of-concept exploit code exists for this vulnerability, which significantly increases the risk to unpatched systems. Systems are only affected where the kernel has been built with CONFIG_WATCH_QUEUE enabled, which is the case for most mainstream distribution kernels from version 5.8 onwards. This exploit has recently been added to the CISA KEV catalogue. 

The vulnerability is assigned CWE-787 (Out-of-bounds Write) and carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 

Affected Software:   

  • Linux kernel 5.8 – 5.16.13 (fixed in 5.10.105, 5.15.28, 5.16.14 and 5.17) 
  • Ubuntu 21.10 
  • Ubuntu 20.04 LTS – HWE and OEM kernels only (5.8, 5.11, 5.13, 5.14); the 5.4 GA kernel is not affected 
  • Ubuntu 22.04 LTS – 5.15 kernels prior to 5.15.0-25.25 

Immediate Actions Required:   

  • Apply the latest kernel patch provided by your Linux distribution vendor to remediate this vulnerability. 
  • Reboot affected systems after patching. Kernel updates do not take effect until the system is restarted, unless a live patching service is in use. 
  • Confirm remediation by verifying the running kernel version with “uname -r” and comparing it against the fixed version published by your vendor. 
  • There is no supported configuration change that mitigates this flaw. Where patching cannot be carried out immediately, restrict local and shell access to trusted administrators only and review accounts with interactive login rights. 

Further Information:   

For detailed information on the vulnerability, please refer to the following sources: 

https://nvd.nist.gov/vuln/detail/CVE-2022-0995 

https://bugzilla.redhat.com/show_bug.cgi?id=2063786 

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=353f7988dd8413c47718f7ca79c030b6fb62cfe5 

For detailed information on how to apply the security patch for this vulnerability, please refer to: 

https://ubuntu.com/security/CVE-2022-0995 

https://www.suse.com/security/cve/CVE-2022-0995.html 

https://security-tracker.debian.org/tracker/CVE-2022-0995 

https://access.redhat.com/security/cve/CVE-2022-0995

Ready to talk? Discuss your low-latency compute requirements with our sales team