← Back to CVE List
Vulnerability Intelligence Report
Linux Kernel Race Condition Vulnerability

CVE-2016-5195

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.0
HIGH
Exploitability:1.1
Impact Score:5.9
EPSS Probability:83.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-362 ↗CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Affected Products & Versions

Vendor Product Affected Versions
canonical ubuntu_linux 12.04, 14.04, 16.04, 16.10
linux linux_kernel all
redhat enterprise_linux 5, 6.0, 7.0
redhat enterprise_linux_aus 6.2, 6.4, 6.5
redhat enterprise_linux_eus 6.6, 6.7, 7.1
redhat enterprise_linux_long_life 5.6, 5.9
redhat enterprise_linux_tus 6.5
debian debian_linux 7.0, 8.0
fedoraproject fedora 23, 24, 25
paloaltonetworks pan-os all
netapp cloud_backup all
netapp hci_storage_nodes all
netapp oncommand_balance all
netapp oncommand_performance_manager all
netapp oncommand_unified_manager_for_clustered_data_ontap all
netapp ontap_select_deploy_administration_utility all
netapp snapprotect all
netapp solidfire all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
83.524%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityChrome · Vendor · USA
Reserved2016-05-31T00:00:00
Published2016-11-10T21:00:00
Patch Date2016-10-20
Last Updated2025-11-04T16:09:08

LINK COPIED TO CLIPBOARD