CVE-2016-5195: Linux Kernel Race Condition Vulnerability
High severity, CVSS 7.0. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 83.5% chance of exploitation in the next 30 days.
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 16.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Fedoraproject Fedora: version 23 only; version 24 only; version 25 only
- Linux Linux Kernel: from 2.6.22, before 3.2.83 (fixed in 3.2.83); from 3.3, before 3.4.113 (fixed in 3.4.113); from 3.5, before 3.10.104 (fixed in 3.10.104); from 3.11, before 3.12.66 (fixed in 3.12.66); from 3.13, before 3.16.38 (fixed in 3.16.38); from 3.17, before 3.18.44 (fixed in 3.18.44); …
- Netapp Cloud Backup: affected versions not specified
- Netapp Hci Storage Nodes: affected versions not specified
- Netapp Oncommand Balance: affected versions not specified
- Netapp Oncommand Performance Manager: affected versions not specified
- Netapp Oncommand Unified Manager For Clustered Data Ontap: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Snapprotect: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Palo Alto Networks PAN-OS: from 5.1, before 7.0.14 (fixed in 7.0.14); from 7.1.0, before 7.1.8 (fixed in 7.1.8)
- Red Hat Enterprise Linux: version 5 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Aus: version 6.2 only; version 6.4 only; version 6.5 only
- Red Hat Enterprise Linux Eus: version 6.6 only; version 6.7 only; version 7.1 only
- Red Hat Enterprise Linux Long Life: version 5.6 only; version 5.9 only
- Red Hat Enterprise Linux Tus: version 6.5 only
Published 2016-11-10. Last modified 2026-06-17.