CVE-2016-5195
Last modified
CVE-2016-5195 is a high-severity vulnerability rated 7/10 on the CVSS scale. Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW.". CISA has confirmed active exploitation in the wild. EPSS estimates a 83.52% chance of exploitation in the next 30 days.
Description
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 16.10 |
| Linux | Linux Kernel | >= 2.6.22, < 3.2.83 |
| Linux | Linux Kernel | >= 3.3, < 3.4.113 |
| Linux | Linux Kernel | >= 3.5, < 3.10.104 |
| Linux | Linux Kernel | >= 3.11, < 3.12.66 |
| Linux | Linux Kernel | >= 3.13, < 3.16.38 |
| Linux | Linux Kernel | >= 3.17, < 3.18.44 |
| Linux | Linux Kernel | >= 3.19, < 4.1.35 |
| Linux | Linux Kernel | >= 4.2, < 4.4.26 |
| Linux | Linux Kernel | >= 4.5, < 4.7.9 |
| Linux | Linux Kernel | >= 4.8, < 4.8.3 |
| Redhat | Enterprise Linux | 5 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Aus | 6.2 |
| Redhat | Enterprise Linux Aus | 6.4 |
| Redhat | Enterprise Linux Aus | 6.5 |
| Redhat | Enterprise Linux Eus | 6.6 |
| Redhat | Enterprise Linux Eus | 6.7 |
| Redhat | Enterprise Linux Eus | 7.1 |
| Redhat | Enterprise Linux Long Life | 5.6 |
| Redhat | Enterprise Linux Long Life | 5.9 |
| Redhat | Enterprise Linux Tus | 6.5 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Fedoraproject | Fedora | 23 |
| Fedoraproject | Fedora | 24 |
| Fedoraproject | Fedora | 25 |
| Paloaltonetworks | Pan-Os | >= 5.1, < 7.0.14 |
| Paloaltonetworks | Pan-Os | >= 7.1.0, < 7.1.8 |
| Netapp | Cloud Backup | All versions |
| Netapp | Hci Storage Nodes | All versions |
| Netapp | Oncommand Balance | All versions |
| Netapp | Oncommand Performance Manager | All versions |
| Netapp | Oncommand Unified Manager For Clustered Data Ontap | All versions |
| Netapp | Ontap Select Deploy Administration Utility | All versions |
| Netapp | Snapprotect | All versions |
| Netapp | Solidfire | All versions |
References
- https://fortiguard.com/advisory/FG-IR-16-063Third Party Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619Issue Tracking, Patch, Vendor Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10770Third Party Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10774Third Party Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10807Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlThird Party Advisory
- https://packetstormsecurity.com/files/139277/Kernel-Live-Patch-Security-Notice-LSN-0012-1.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139286/DirtyCow-Linux-Kernel-Race-Condition.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139287/DirtyCow-Local-Root-Proof-Of-Concept.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139922/Linux-Kernel-Dirty-COW-PTRACE_POKEDATA-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139923/Linux-Kernel-Dirty-COW-PTRACE_POKEDATA-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/142151/Kernel-Live-Patch-Security-Notice-LSN-0021-1.htmlThird Party Advisory, VDB Entry
- https://rhn.redhat.com/errata/RHSA-2016-2098.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2105.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2106.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2107.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2110.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2118.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2120.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2124.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2126.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2127.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2128.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2132.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2133.htmlThird Party Advisory
- https://www.debian.org/security/2016/dsa-3696Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/21/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/26/7Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/27/13Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/30/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/11/03/7Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/07/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/2Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/7Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/8Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/09/4Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/15/1Mailing List, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- https://www.securityfocus.com/archive/1/539611/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/540252/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/540344/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/540736/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/539611/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/540252/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/540344/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/540736/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/93793Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id/1037078Broken Link, Third Party Advisory, VDB Entry
- https://www.ubuntu.com/usn/USN-3104-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3104-2Third Party Advisory
- https://www.ubuntu.com/usn/USN-3105-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3105-2Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-2Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-3Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-4Third Party Advisory
- https://www.ubuntu.com/usn/USN-3107-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3107-2Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0372Broken Link, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-5195Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/2706661Third Party Advisory
- https://bto.bluecoat.com/security-advisory/sa134Permissions Required, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1384344Exploit, Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1004418Issue Tracking
- https://dirtycow.ninjaThird Party Advisory
- https://github.com/dirtycow/dirtycow.github.io/wiki/PoCsThird Party Advisory
- https://github.com/dirtycow/dirtycow.github.io/wiki/VulnerabilityDetailsExploit, Third Party Advisory
- https://github.com/torvalds/linux/commit/19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619Issue Tracking, Patch
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+FixesBroken Link, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10176Broken Link, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10177Broken Link, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10222Broken Link, Third Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-5195.htmlThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2016-5195Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20161025-0001/Third Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-5195Third Party Advisory
- https://source.android.com/security/bulletin/2016-11-01.htmlThird Party Advisory
- https://source.android.com/security/bulletin/2016-12-01.htmlThird Party Advisory
- https://www.exploit-db.com/exploits/40611/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40616/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40839/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40847/Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/243144Third Party Advisory, US Government Resource
- https://fortiguard.com/advisory/FG-IR-16-063Third Party Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619Issue Tracking, Patch, Vendor Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10770Third Party Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10774Third Party Advisory
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10807Third Party Advisory
- https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlThird Party Advisory
- https://packetstormsecurity.com/files/139277/Kernel-Live-Patch-Security-Notice-LSN-0012-1.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139286/DirtyCow-Linux-Kernel-Race-Condition.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139287/DirtyCow-Local-Root-Proof-Of-Concept.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139922/Linux-Kernel-Dirty-COW-PTRACE_POKEDATA-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/139923/Linux-Kernel-Dirty-COW-PTRACE_POKEDATA-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/142151/Kernel-Live-Patch-Security-Notice-LSN-0021-1.htmlThird Party Advisory, VDB Entry
- https://rhn.redhat.com/errata/RHSA-2016-2098.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2105.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2106.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2107.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2110.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2118.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2120.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2124.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2126.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2127.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2128.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2132.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2133.htmlThird Party Advisory
- https://seclists.org/fulldisclosure/2024/Aug/35Mailing List, Third Party Advisory
- https://www.debian.org/security/2016/dsa-3696Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/21/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/26/7Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/27/13Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/10/30/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/11/03/7Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/07/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/2Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/7Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/08/8Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/09/4Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/15/1Mailing List, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- https://www.securityfocus.com/archive/1/539611/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/540252/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/540344/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/540736/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/539611/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/540252/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/540344/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/archive/1/archive/1/540736/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/93793Broken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id/1037078Broken Link, Third Party Advisory, VDB Entry
- https://www.ubuntu.com/usn/USN-3104-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3104-2Third Party Advisory
- https://www.ubuntu.com/usn/USN-3105-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3105-2Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-2Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-3Third Party Advisory
- https://www.ubuntu.com/usn/USN-3106-4Third Party Advisory
- https://www.ubuntu.com/usn/USN-3107-1Third Party Advisory
- https://www.ubuntu.com/usn/USN-3107-2Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0372Broken Link, Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-5195Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/2706661Third Party Advisory
- https://bto.bluecoat.com/security-advisory/sa134Permissions Required, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1384344Exploit, Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1004418Issue Tracking
- https://dirtycow.ninjaThird Party Advisory
- https://github.com/dirtycow/dirtycow.github.io/wiki/PoCsThird Party Advisory
- https://github.com/dirtycow/dirtycow.github.io/wiki/VulnerabilityDetailsExploit, Third Party Advisory
- https://github.com/torvalds/linux/commit/19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619Issue Tracking, Patch
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+FixesBroken Link, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10176Broken Link, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10177Broken Link, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10222Broken Link, Third Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-5195.htmlThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2016-5195Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20161025-0001/Third Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-5195Third Party Advisory
- https://source.android.com/security/bulletin/2016-11-01.htmlThird Party Advisory
- https://source.android.com/security/bulletin/2016-12-01.htmlThird Party Advisory
- https://www.exploit-db.com/exploits/40611/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40616/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40839/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40847/Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/243144Third Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-5195US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2016-5195?
How severe is CVE-2016-5195?
How do I fix CVE-2016-5195?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-5189Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Li…
- CVE-2016-5190Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Li…
- CVE-2016-5191Bookmark handling in Google Chrome prior to 54.0.2840.59 for…
- CVE-2016-5192Blink in Google Chrome prior to 54.0.2840.59 for Windows mis…
- CVE-2016-5193Google Chrome prior to 54.0 for iOS had insufficient validat…
- CVE-2016-5194Unspecified vulnerabilities in Google Chrome before 54.0.284…9.8
- CVE-2016-5196The content renderer client in Google Chrome prior to 54.0.2…
- CVE-2016-5197The content view client in Google Chrome prior to 54.0.2840.…
- CVE-2016-5198V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.…8.8
- CVE-2016-5199An off by one error resulting in an allocation of zero size …
- CVE-2016-5200V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.…
- CVE-2016-5201A leak of privateClass in the extensions API in Google Chrom…
Are you affected by CVE-2016-5195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
