peter bassill · operator
$ cve CVE-2016-5195 JSON

CVE-2016-5195 KEV EXPLOIT

7.0
HIGH · CVSS 3.1 · EPSS 83.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

Scoring

CVSS7.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS83.52% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-362
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2016-11-10
Last modified2026-06-17

CISA KEV

NameLinux Kernel Race Condition Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (18)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
linuxlinux kernel
netappcloud backup
netapphci storage nodes
netapponcommand balance
netapponcommand performance manager
netapponcommand unified manager for clustered data ontap
netappontap select deploy administration utility
netappsnapprotect
netappsolidfire
paloaltonetworkspan-os
redhatenterprise linux
redhatenterprise linux aus
redhatenterprise linux eus
redhatenterprise linux long life
redhatenterprise linux tus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD