Junglewise Threat Intelligence

CVE-2016-5195: Linux Kernel Race Condition Vulnerability

CVE-2016-5195 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2022-03-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition in the Linux kernel's mm/gup.c, known as 'Dirty COW', allows local users to gain privileges by leveraging incorrect handling of the copy-on-write (COW) feature. An attacker can exploit this to write to read-only memory mappings.

Affected products

  • Linux Linux Kernel 2.x through 4.x before 4.8.3

Timeline

  • 2016-10: exploited: Exploited in the wild in October 2016.
  • 2022-03-03: disclosed

Related threats