IM
IronMonkey Threat Research

CVE-2016-5195 HIGH

Published: 2016-11-10 | Last Modified: 2026-06-17 | Status: Analyzed

Description

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

Additional Descriptions (1)

La condición de carrera en mm / gup.c en el kernel de Linux 2.x a 4.x antes de 4.8.3 permite a los usuarios locales obtener privilegios aprovechando el manejo incorrecto de una función copy-on-write (COW) para escribir en un read- only la cartografía de la memoria, como explotados en la naturaleza en octubre de 2016, vulnerabilidad también conocida como "Dirty COW".

CVSS Metrics

Base Score: 7.0 (HIGH)

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.0

Impact Score: 5.9

Base Score: 7.2 (HIGH)

AV:L/AC:L/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-362
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-362

Affected Products

Vendor Product Version Update Type
canonical ubuntu_linux 12.04 <built-in method update of dict object at 0x7e60bbd60340> Operating System
canonical ubuntu_linux 14.04 <built-in method update of dict object at 0x7e60bbd62c40> Operating System
canonical ubuntu_linux 16.04 <built-in method update of dict object at 0x7e60b9fb4100> Operating System
canonical ubuntu_linux 16.10 <built-in method update of dict object at 0x7e60b9fb5a80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60bbd60680> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60bbd61340> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60bbd63dc0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60b9fb7b40> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60b9fb4e40> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60bbd63800> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60eb25c740> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e6112352f00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60eb226600> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7e60a888fc80> Operating System
redhat enterprise_linux 5 <built-in method update of dict object at 0x7e6110a554c0> Operating System
redhat enterprise_linux 6.0 <built-in method update of dict object at 0x7e6112cb4580> Operating System
redhat enterprise_linux 7.0 <built-in method update of dict object at 0x7e60a88a90c0> Operating System
redhat enterprise_linux_aus 6.2 <built-in method update of dict object at 0x7e60a88a9040> Operating System
redhat enterprise_linux_aus 6.4 <built-in method update of dict object at 0x7e6111c1d2c0> Operating System
redhat enterprise_linux_aus 6.5 <built-in method update of dict object at 0x7e613c198dc0> Operating System
redhat enterprise_linux_eus 6.6 <built-in method update of dict object at 0x7e613cf7c680> Operating System
redhat enterprise_linux_eus 6.7 <built-in method update of dict object at 0x7e61123033c0> Operating System
redhat enterprise_linux_eus 7.1 <built-in method update of dict object at 0x7e6134291b00> Operating System
redhat enterprise_linux_long_life 5.6 <built-in method update of dict object at 0x7e6110a55e80> Operating System
redhat enterprise_linux_long_life 5.9 <built-in method update of dict object at 0x7e6110a57480> Operating System
redhat enterprise_linux_tus 6.5 <built-in method update of dict object at 0x7e6110a56900> Operating System
debian debian_linux 7.0 <built-in method update of dict object at 0x7e6110a55ac0> Operating System
debian debian_linux 8.0 <built-in method update of dict object at 0x7e6110a56080> Operating System
fedoraproject fedora 23 <built-in method update of dict object at 0x7e61342d2a80> Operating System
fedoraproject fedora 24 <built-in method update of dict object at 0x7e613c4dedc0> Operating System
fedoraproject fedora 25 <built-in method update of dict object at 0x7e6112304900> Operating System
paloaltonetworks pan-os * <built-in method update of dict object at 0x7e60bafaeb40> Operating System
paloaltonetworks pan-os * <built-in method update of dict object at 0x7e60e8874580> Operating System
netapp cloud_backup - <built-in method update of dict object at 0x7e60e8875f40> Application
netapp hci_storage_nodes - <built-in method update of dict object at 0x7e60e8875f80> Application
netapp oncommand_balance - <built-in method update of dict object at 0x7e62aa3d11c0> Application
netapp oncommand_performance_manager - <built-in method update of dict object at 0x7e613cfc3b80> Application
netapp oncommand_unified_manager_for_clustered_data_ontap - <built-in method update of dict object at 0x7e61079cbc00> Application
netapp ontap_select_deploy_administration_utility - <built-in method update of dict object at 0x7e60eb25f9c0> Application
netapp snapprotect - <built-in method update of dict object at 0x7e60eb25dc40> Application
netapp solidfire - <built-in method update of dict object at 0x7e60eb25db80> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_aus:6.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_aus:6.4:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_aus:6.5:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_eus:6.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_eus:6.7:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_eus:7.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_long_life:5.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_long_life:5.9:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_tus:6.5:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
Yes cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
Yes cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:hci_storage_nodes:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:oncommand_performance_manager:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:oncommand_unified_manager_for_clustered_data_ontap:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:snapprotect:-:*:*:*:*:*:*:*
Yes cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*

References

Notification
Message here