CVE-2016-5195
Confirmed PUBLISHEDRace condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
- CVE Published
- Nov 10, 2016
- Exploitation Reported
- Mar 03, 2022
- CVSS
- 7.0 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a |
n/a
|
n/a |
Affected |
CVE References
- RHSA-2016:2107 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2107.html
- RHSA-2017:0372 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:0372
- RHSA-2016:2118 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2118.html
- RHSA-2016:2128 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2128.html
- RHSA-2016:2120 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2120.html
Show 121 more references
- RHSA-2016:2133 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2133.html
- RHSA-2016:2098 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2098.html
- RHSA-2016:2127 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2127.html
- RHSA-2016:2106 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2106.html
- RHSA-2016:2124 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2124.html
- RHSA-2016:2105 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2105.html
- RHSA-2016:2126 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2126.html
- RHSA-2016:2132 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2132.html
- RHSA-2016:2110 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2016-2110.html
- SUSE-SU-2016:2635 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00055...
- SUSE-SU-2016:2659 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00067...
- USN-3106-2 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3106-2
- openSUSE-SU-2016:2583 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00034...
- SUSE-SU-2016:2633 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00053...
- SUSE-SU-2016:2638 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00058...
- openSUSE-SU-2016:2584 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00035...
- SUSE-SU-2016:2658 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00066...
- SUSE-SU-2016:2631 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00051...
- USN-3106-3 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3106-3
- SUSE-SU-2016:2655 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00064...
- FEDORA-2016-c3558808cd lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- SUSE-SU-2016:2637 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00057...
- SUSE-SU-2016:2596 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00040...
- SUSE-SU-2016:2634 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00054...
- 20181107 Cisco TelePresence Video Communication Server Test Validation Script Issue tools.cisco.com · Vendor Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory...
- 20161026 Vulnerability in Linux Kernel Affecting Cisco Products: October 2016 tools.cisco.com · Vendor Advisory http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/...
- SUSE-SU-2016:2657 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00065...
- SUSE-SU-2016:2614 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00045...
- USN-3105-2 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3105-2
- USN-3107-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3107-1
- USN-3107-2 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3107-2
- openSUSE-SU-2016:2625 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048...
- USN-3106-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3106-1
- USN-3106-4 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3106-4
- SUSE-SU-2016:2673 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00072...
- USN-3104-2 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3104-2
- SUSE-SU-2016:2629 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00049...
- SUSE-SU-2016:2632 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00052...
- USN-3105-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3105-1
- SUSE-SU-2016:2630 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00050...
- FEDORA-2016-db4b75b352 lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- FEDORA-2016-c8a0c7eece lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- SUSE-SU-2016:2636 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00056...
- SUSE-SU-2016:3069 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033...
- DSA-3696 debian.org · Vendor Advisory http://www.debian.org/security/2016/dsa-3696
- SUSE-SU-2016:2592 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00038...
- USN-3104-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-3104-1
- SUSE-SU-2016:2593 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00039...
- SUSE-SU-2016:3304 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100...
- SUSE-SU-2016:2585 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00036...
- openSUSE-SU-2016:2649 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063...
- openSUSE-SU-2020:0554 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041...
- VU#243144 kb.cert.org · Third-Party Advisory https://www.kb.cert.org/vuls/id/243144
- 40616 exploit-db.com · Exploit https://www.exploit-db.com/exploits/40616/
- 40839 exploit-db.com · Exploit https://www.exploit-db.com/exploits/40839/
- 40847 exploit-db.com · Exploit https://www.exploit-db.com/exploits/40847/
- 40611 exploit-db.com · Exploit https://www.exploit-db.com/exploits/40611/
- 1037078 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1037078
- 93793 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/93793
- [oss-security] 20161026 Re: CVE-2016-5195 "Dirty COW" Linux kernel privilege escalation vulnerability openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2016/10/26/7
- [oss-security] 20161027 CVE-2016-5195 test case openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2016/10/27/13
- 20170615 [security bulletin] HPESBGN03761 rev.1 - HPE Virtualization Performance Viewer (VPV)/ Cloud Optimizer using Linux, Remote Escalation of Privilege securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/archive/1/540736/100/0/threaded
- 20170331 [security bulletin] HPESBGN03722 rev.1 - HPE Operations Agent, Local Escalation of Privilege securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/540344/100/0/threaded
- [oss-security] 20161030 Re: CVE-2016-5195 test case openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2016/10/30/1
- 20161020 [CVE-2016-5195] "Dirty COW" Linux privilege escalation vulnerability securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/539611/100/0/threaded
- 20170310 [security bulletin] HPESBGN03707 rev.1 - HPE ConvergedSystem 700 2.0 VMware Kit, Remote Increase of Privilege securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/archive/1/540252/100/0/threaded
- [oss-security] 20161103 Re: CVE-2016-5195 "Dirty COW" Linux kernel privilege escalation vulnerability openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2016/11/03/7
- 20170331 [security bulletin] HPESBGN03722 rev.1 - HPE Operations Agent, Local Escalation of Privilege securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/archive/1/540344/100/0/threaded
- 20161020 [CVE-2016-5195] "Dirty COW" Linux privilege escalation vulnerability securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/archive/1/539611/100/0/threaded
- 20170615 [security bulletin] HPESBGN03761 rev.1 - HPE Virtualization Performance Viewer (VPV)/ Cloud Optimizer using Linux, Remote Escalation of Privilege securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/540736/100/0/threaded
- [oss-security] 20161021 CVE-2016-5195 "Dirty COW" Linux kernel privilege escalation vulnerability openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2016/10/21/1
- 20170310 [security bulletin] HPESBGN03707 rev.1 - HPE ConvergedSystem 700 2.0 VMware Kit, Remote Increase of Privilege securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/540252/100/0/threaded
- [oss-security] 20220307 CVE-2022-0847: Linux kernel: overwriting read-only files openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/03/07/1
- [oss-security] 20220808 Re: CVE-2022-2590: Linux kernel: Modifying shmem/tmpfs files without write permissions openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/08/08/2
- [oss-security] 20220808 CVE-2022-2590: Linux kernel: Modifying shmem/tmpfs files without write permissions openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/08/08/1
- [oss-security] 20220808 Re: CVE-2022-2590: Linux kernel: Modifying shmem/tmpfs files without write permissions openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/08/08/7
- [oss-security] 20220808 Re: CVE-2022-2590: Linux kernel: Modifying shmem/tmpfs files without write permissions openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/08/08/8
- [oss-security] 20220809 Re: CVE-2022-2590: Linux kernel: Modifying shmem/tmpfs files without write permissions openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/08/09/4
- [oss-security] 20220815 Re: CVE-2022-2590: Linux kernel: Modifying shmem/tmpfs files without write permissions openwall.com · Mailing List http://www.openwall.com/lists/oss-security/2022/08/15/1
- bto.bluecoat.com/security-advisory/sa134 bto.bluecoat.com · CVE Record https://bto.bluecoat.com/security-advisory/sa134
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?doc...
- oracle.com/technetwork/security-advisory/cpujul2018-425... oracle.com · CVE Record http://www.oracle.com/technetwork/security-advisory/cpujul2018-425824...
- dirtycow.ninja dirtycow.ninja · CVE Record https://dirtycow.ninja
- source.android.com/security/bulletin/2016-12-01.html source.android.com · CVE Record https://source.android.com/security/bulletin/2016-12-01.html
- h20566.www2.hpe.com/hpsc/doc/public/display h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&d...
- bugzilla.suse.com/show_bug.cgi bugzilla.suse.com · CVE Record https://bugzilla.suse.com/show_bug.cgi?id=1004418
- people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-5195.html people.canonical.com · CVE Record https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-5195....
- h20566.www2.hpe.com/hpsc/doc/public/display h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&d...
- security.netapp.com/advisory/ntap-20161025-0001 security.netapp.com · CVE Record https://security.netapp.com/advisory/ntap-20161025-0001/
- security-tracker.debian.org/tracker/CVE-2016-5195 security-tracker.debian.org · CVE Record https://security-tracker.debian.org/tracker/CVE-2016-5195
- GitHub — dirtycow/dirtycow.github.io github.com · CVE Record https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs
- h20566.www2.hpe.com/hpsc/doc/public/display h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&d...
- GitHub — torvalds/linux github.com · CVE Record https://github.com/torvalds/linux/commit/19be0eaffa3ac7d8eb6784ad9bdb...
- help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Cen... help.ecostruxureit.com · CVE Record https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Da...
- GitHub — dirtycow/dirtycow.github.io github.com · CVE Record https://github.com/dirtycow/dirtycow.github.io/wiki/VulnerabilityDetails
- bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=1384344
- access.redhat.com/security/vulnerabilities/2706661 access.redhat.com · CVE Record https://access.redhat.com/security/vulnerabilities/2706661
- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit git.kernel.org · CVE Record http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit...
- access.redhat.com/security/cve/cve-2016-5195 access.redhat.com · CVE Record https://access.redhat.com/security/cve/cve-2016-5195
- source.android.com/security/bulletin/2016-11-01.html source.android.com · CVE Record https://source.android.com/security/bulletin/2016-11-01.html
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?doc...
- kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.3 kernel.org · CVE Record http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.8.3
- h20566.www2.hpe.com/hpsc/doc/public/display h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&d...
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?doc...
- kc.mcafee.com/corporate/index kc.mcafee.com · CVE Record https://kc.mcafee.com/corporate/index?page=content&id=SB10176
- packetstormsecurity.com/files/139277/Kernel-Live-Patch-Security-Noti... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/139277/Kernel-Live-Patch-Securit...
- huawei.com/en/psirt/security-advisories/huawei-sa-20161... huawei.com · CVE Record http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161207...
- packetstormsecurity.com/files/142151/Kernel-Live-Patch-Security-Noti... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/142151/Kernel-Live-Patch-Securit...
- h20566.www2.hpe.com/hpsc/doc/public/display h20566.www2.hpe.com · CVE Record https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&d...
- kb.juniper.net/InfoCenter/index kb.juniper.net · CVE Record http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10770
- kc.mcafee.com/corporate/index kc.mcafee.com · CVE Record https://kc.mcafee.com/corporate/index?page=content&id=SB10177
- kb.juniper.net/InfoCenter/index kb.juniper.net · CVE Record http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10774
- packetstormsecurity.com/files/139923/Linux-Kernel-Dirty-COW-PTRACE_P... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/139923/Linux-Kernel-Dirty-COW-PT...
- fortiguard.com/advisory/FG-IR-16-063 fortiguard.com · CVE Record http://fortiguard.com/advisory/FG-IR-16-063
- kb.juniper.net/InfoCenter/index kb.juniper.net · CVE Record http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10807
- packetstormsecurity.com/files/139922/Linux-Kernel-Dirty-COW-PTRACE_P... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/139922/Linux-Kernel-Dirty-COW-PT...
- packetstormsecurity.com/files/139286/DirtyCow-Linux-Kernel-Race-Cond... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/139286/DirtyCow-Linux-Kernel-Rac...
- kc.mcafee.com/corporate/index kc.mcafee.com · CVE Record https://kc.mcafee.com/corporate/index?page=content&id=SB10222
- packetstormsecurity.com/files/139287/DirtyCow-Local-Root-Proof-Of-Co... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/139287/DirtyCow-Local-Root-Proof...
- security.paloaltonetworks.com/CVE-2016-5195 security.paloaltonetworks.com · CVE Record https://security.paloaltonetworks.com/CVE-2016-5195
- arista.com/en/support/advisories-notices/security-advis... arista.com · CVE Record https://www.arista.com/en/support/advisories-notices/security-advisor...
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-03-03 00:00 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitation Status
Exploited in the wild
Recorded 2022-03-03 00:00:00 UTC · CISA
Proof of concept available
Recorded 2016-10-21 05:30:17 UTC · GitHub
Weaknesses (CWE)
-
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2023-12-15 07:47:39 UTC · 0 stars
github · Created 2023-11-29 03:34:10 UTC · 0 stars
github · Created 2023-10-26 01:54:49 UTC · 0 stars
github · Created 2022-11-29 09:56:20 UTC · 0 stars
github · Created 2022-05-18 10:51:23 UTC · 1 stars
The Repository contains documents that explains the explotation of CVE-2016-5195
github · Created 2022-04-08 18:18:36 UTC · 1 stars
Ported golang version of dirtycow.c
github · Created 2022-01-17 08:45:28 UTC · 0 stars
github · Created 2021-04-16 05:59:04 UTC · 2 stars
my personal POC of CVE-2016-5195(dirtyCOW)
github · Created 2020-12-20 19:17:10 UTC · 1 stars
DirtyCOW Exploit for Android
github · Created 2020-05-12 17:10:38 UTC · 0 stars
This is a Dirty Cow (CVE-2016-5195) privilege escalation vulnerability exploit
github · Created 2020-05-11 19:25:26 UTC · 0 stars
github · Created 2019-11-26 01:18:41 UTC · 0 stars
Exploit the dirtycow vulnerability to login as root
github · Created 2017-12-06 17:36:19 UTC · 0 stars
github · Created 2017-10-19 02:04:50 UTC · 1 stars
Dirty COW (CVE-2016-5195) Testing
github · Created 2017-01-15 03:56:27 UTC · 0 stars
github · Created 2016-12-08 22:41:51 UTC · 0 stars
Inspec profile for detecting CVE-2016-5195 aka Dirty COW
github · Created 2016-11-06 14:38:04 UTC · 0 stars
Recent Linux privilege escalation exploit
github · Created 2016-10-29 19:15:20 UTC · 6 stars
github · Created 2016-10-23 00:16:33 UTC · 326 stars
A CVE-2016-5195 exploit example.
github · Created 2016-10-21 11:19:21 UTC · 973 stars
CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android
github · Created 2016-10-21 06:06:05 UTC · 1 stars
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
21:00 UTC over 9 years ago21:00 UTC · over 9 years ago
CVE published
Vulnerability disclosed publicly
-
05:30 UTC almost 10 years ago05:30 UTC · almost 10 years ago
Public PoC available
Public proof-of-concept code published
-
00:00 UTC about 10 years ago00:00 UTC · about 10 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2016-5195
{
"cve_id": "CVE-2016-5195",
"title": "Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 a...",
"affected_vendor": "Linux",
"affected_product": "Linux Kernel",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.0,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}