← All CVEs

CVE-2016-5195

high · 7Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

7
CVSS
83.5%
EPSS (exploit prob.)
100th
EPSS percentile
2016-11-10
Published

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-362

Affected products

VendorProductAffected versions
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux16.10
linuxlinux_kernel>= 2.6.22, < 3.2.83
linuxlinux_kernel>= 3.3, < 3.4.113
linuxlinux_kernel>= 3.5, < 3.10.104
linuxlinux_kernel>= 3.11, < 3.12.66
linuxlinux_kernel>= 3.13, < 3.16.38
linuxlinux_kernel>= 3.17, < 3.18.44
linuxlinux_kernel>= 3.19, < 4.1.35
linuxlinux_kernel>= 4.2, < 4.4.26
linuxlinux_kernel>= 4.5, < 4.7.9
linuxlinux_kernel>= 4.8, < 4.8.3
redhatenterprise_linux5
redhatenterprise_linux6.0
redhatenterprise_linux7.0
redhatenterprise_linux_aus6.2
redhatenterprise_linux_aus6.4
redhatenterprise_linux_aus6.5
redhatenterprise_linux_eus6.6
redhatenterprise_linux_eus6.7
redhatenterprise_linux_eus7.1
redhatenterprise_linux_long_life5.6
redhatenterprise_linux_long_life5.9
redhatenterprise_linux_tus6.5
debiandebian_linux7.0
debiandebian_linux8.0
fedoraprojectfedora23
fedoraprojectfedora24
fedoraprojectfedora25
paloaltonetworkspan-os>= 5.1, < 7.0.14
paloaltonetworkspan-os>= 7.1.0, < 7.1.8
netappcloud_backupall versions
netapphci_storage_nodesall versions
netapponcommand_balanceall versions
netapponcommand_performance_managerall versions
netapponcommand_unified_manager_for_clustered_data_ontapall versions
netappontap_select_deploy_administration_utilityall versions
netappsnapprotectall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-5195