cbcvebase.
CVE-2016-5195
published 2016-11-10

CVE-2016-5195: Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a…

PriorityP190high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
83.01%
99.6th percentile
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.7.8-1 (bookworm)linux 4.7.8-1 (bookworm)
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
googleandroid
linuxlinux
linuxlinux>= 9ae0f87d009ca6c4aab2882641ddfc319727e3db < 9def52eb10baab3b700858003d462fcf17d628739def52eb10baab3b700858003d462fcf17d62873
linuxlinux>= 9ae0f87d009ca6c4aab2882641ddfc319727e3db < 5535be3099717646781ce1540cf725965d680e7b5535be3099717646781ce1540cf725965d680e7b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 4.7.8-14.7.8-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 4.7.8-14.7.8-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 4.7.8-14.7.8-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 4.7.8-14.7.8-1
linuxlinux_kernel>= 2.6.22 < 3.2.833.2.83
linuxlinux_kernel>= 3.11 < 3.12.663.12.66

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://pastebin.com (POC code posted six days after disclosure)
  • CVE-2016-5195 (Dirty COW) is actively exploited for privilege escalation on Linux systems by multiple threat actors including CL-STA-0969 (Liminal Panda overlap) and Earth Krahang; monitor for exploitation attempts on Linux hosts, especially in telecom and government environments.
  • Earth Krahang exploits CVE-2016-5195 for privilege escalation on Linux systems alongside CVE-2021-4034 and CVE-2021-22555; correlate with post-exploitation activity on Linux government servers.
  • CVE-2016-5195 POC exploit code appeared on Pastebin approximately six days after initial disclosure on October 19, 2016, and was available two weeks before NVD publication on November 10, 2016; treat any pre-patch window as high-risk for active exploitation.
  • Within two days of CVE-2016-5195 disclosure, exploit information was translated to Russian and posted on a Russian criminal forum; monitor dark/deep web and criminal forums for early exploit discussion as an indicator of imminent weaponization.
  • The root cause of CVE-2016-5195 involves a write-protected PTE being set dirty, allowing FOLL_FORCE to erroneously grant write access to R/O-mapped shared pages; detection should focus on unexpected write access to read-only memory mappings and COW bypass conditions.
  • ·CVE-2016-5195 (Dirty COW) exploitation via UFFDIO_CONTINUE/FOLL_FORCE path (CVE-2022-2590 variant) is limited to x86_64 and aarch64 architectures that support CONFIG_HAVE_ARCH_USERFAULTFD_MINOR.
  • ·The FinSpy exploitation of CVE-2016-5195 on Android requires the victim device to be running an outdated OS kernel; devices with patched kernels are not vulnerable to this specific attack vector.

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.0HIGH
vulncheck7.0HIGH
cisa7.0HIGH
vendor_cisco7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.