CVE-2016-5195: Linux Kernel Race Condition Vulnerability
A race condition was found in the way Linux kernel's memory subsystem handled breakage of the read only private mappings COW situation on write access.
An unprivileged local user could use this flaw to gain write access to otherwise read only memory mappings and thus increase their privileges on the system.
Red Hat is aware of this issue and if you have questions about the affectedness of your system please contact Red Hat Support. For additional information see https://access.redhat.com/security/vulnerabilities/2706661
Other sources
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.8.3 - Compensating control
Apply Red Hat Support guidance for affectedness assessment (Red Hat is aware of the issue; contact Red Hat Support if you have questions about whether your system is affected).
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5195?
CVE-2016-5195 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2016-5195?
To fix CVE-2016-5195, update your Linux kernel to a version that has addressed this vulnerability.
Which Linux kernel versions are affected by CVE-2016-5195?
CVE-2016-5195 affects multiple versions of the Linux kernel from 2.6.22 up to version 4.8.3.
Can unprivileged users exploit CVE-2016-5195?
Yes, unprivileged local users can exploit CVE-2016-5195 to gain unauthorized write access to read-only memory mappings.
What systems are impacted by CVE-2016-5195?
CVE-2016-5195 impacts various systems, including Ubuntu, Red Hat Enterprise Linux, and Debian.