Skip to main content

CVE detail

CVE-2016-5195

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

CVSS 7.0 · HighBuzz score 72.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 72.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
31 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
31 source links · newest first
  • CSOs must ensure their Linux-based systems block unauthorized privilege escalation until distros release patches to plug a serious kernel vulnerability affecting all Linux distributions shipped since 2017. Until fixes are available for what’s been dubbed the Copy Fail logic bug (CVE-2026-31431), which lets users easily obtain root access, there isn’t much CSOs can do, says […]

    newswww.csoonline.comMay 1, 2026, 1:14 AM
  • State-backed group CL-STA-0969 hit Southeast Asian telecoms in 2024, targeting critical infrastructure, says Palo Alto Networks’ Unit 42. Palo Alto Networks reported that a nation-state actor, tracked as CL-STA-0969, targeted telecom firms in Southeast Asia, with attacks on critical infrastructure from February to November 2024. Threat actor CL-STA-0969 overlaps with the China-linked cyber espionage group […]

    newssecurityaffairs.comAug 4, 2025, 7:29 AM
  • Recent activity targeting telecom infrastructure is assessed with high confidence to overlap with Liminal Panda activity. The actors used custom tools, tunneling and OPSEC tactics for stealth.

    vendorunit42.paloaltonetworks.comJul 29, 2025, 9:00 PM
  • The Ebury Linux botnet has ensnared over 400,000 Linux systems in 15 years, with roughly 100,000 still infected.

    newswww.securityweek.comMay 15, 2024, 11:23 AM
  • Ongoing Xurum attacks target Magento 2 e-storesSecurity Affairs

    Experts warn of ongoing attacks, dubbed Xurum, targeting e-commerce websites using Adobe’s Magento 2 CMS. Akamai researchers warn of ongoing attacks, dubbed Xurum, targeting e-commerce websites running the Magento 2 CMS. The attackers are actively exploiting a server-side template injection issue, tracked as CVE-2022-24086, (CVSS score: 9.8), in Adobe Commerce and Magento Open Source. The […]

    newssecurityaffairs.comAug 14, 2023, 5:46 PM
  • Academic researchers from Northwestern University have shared details on ‘DirtyCred’, a previously unknown privilege escalation vulnerability affecting the Linux kernel.

    newswww.securityweek.comAug 23, 2022, 12:35 PM
  • Dirty Pipe is a Linux vulnerability, tracked as CVE-2022-0847, that can allow local users to gain root privileges on all major distros. Security expert Max Kellermann discovered a Linux flaw, dubbed Dirty Pipe and tracked as CVE-2022-0847, that can allow local users to gain root privileges on all major distros. The vulnerability affects Linux Kernel […]

    newssecurityaffairs.comMar 8, 2022, 7:53 AM
  • Trend Micro released a research urging organizations to focus patching efforts on the vulnerabilities that pose the greatest risk to their organization, even if they are years old. Older exploits for sale more popular with criminals The research found that 22% of exploits for sale in underground forums are more than three years old. “Criminals know that organizations are struggling to prioritize and patch promptly, and our research shows that patch delays are frequently taken … More →

    newswww.helpnetsecurity.comJul 15, 2021, 6:00 AM
  • Currently available container-based infrastructure has limitations because containers are not truly sandboxed and share the host OS kernel. The root of the problem is the weak separation between containers when the host OS creates a virtualized userland for each container. This blog covers four unique projects from IBM, Google, Amazon, and OpenStack, respectively, that use different techniques to achieve the same goal, creating stronger isolation for containers. The overview in this blog of state of the art research should help readers prepare for the upcoming transformation.

    vendorunit42.paloaltonetworks.comJun 6, 2019, 1:00 PM
  • In the last weeks, a new Android surveillance malware dubbed Exodus made the headlines, now expert found the iOS version of the government spyware. Security experts at LookOut have discovered an iOS version of the dreaded surveillance Android app Exodus that was initially found on the official Google Play Store. Exodus for Android is a […]

    newssecurityaffairs.comApr 9, 2019, 8:34 PM
  • Security experts from Russian antivirus firm Dr.Web have discovered a new strain of Linux cryptominer tracked as Linux.BtcMine.174. The Linux cryptominer has a multicomponent structure that implements a broad range of features in over 1,000 lines of code. When the Monero Linux cryptominer is first executed it checks whether the server, from which the Trojan will subsequently […]

    newssecurityaffairs.comNov 26, 2018, 9:11 AM
  • In an advisory published yesterday, Mozilla disclosed the presence of nine security flaws in Firefox 61 which have been patched in the latest release of the browser. Some of the bugs are severe, but at this time do not appear to be receiving attacks in the wild. To protect yourself as a Firefox user, ensure … Read More

    vendorwww.wordfence.comSep 6, 2018, 11:59 PM
  • Researchers discovered that the original patch for the Dirty COW vulnerability (CVE-2016-5195) is affected by a security flaw. The original patch for the Dirty COW vulnerability (CVE-2016-5195) is affected by a security flaw that could be exploited by an attacker to run local code on affected systems and exploit a race condition to perform a privilege escalation […]

    newssecurityaffairs.comDec 1, 2017, 8:37 PM
  • In a world of state-sponsored hackers, highly motivated cybercrime gangs and determined hacktivists, mitigating software vulnerabilities is an essential part of the job for IT security teams. Many look to authoritative centralised sources to help manage their risk exposure, like the US government’s National Vulnerability Database (NVD). However, new research has found that bugs appear […]

    newswww.csoonline.comNov 9, 2017, 1:30 AM
  • Security experts at Trend Micro have recently spotted a new strain of Android malware, dubbed ZNIU, that exploits the Dirty COW Linux kernel vulnerability. The Dirty COW vulnerability was discovered by the security expert Phil Oester in October 2016, it could be exploited by a local attacker to escalate privileges. The name ‘Dirty COW’ is due to the fact that it’s […]

    newssecurityaffairs.comSep 27, 2017, 5:20 AM
  • A recently discovered piece of Android malware is exploiting the infamous “ Dirty COW “ Linux vulnerability discover

    newswww.securityweek.comSep 26, 2017, 4:06 PM
  • From over 12,500 disclosed Common Vulnerabilities and Exposures (CVEs), more than 75% were publicly reported online before they were published to the NIST’s centralized National Vulnerability Database (NVD), Recorded Future researchers have found. The data, taken from the beginning of 2016, showed that the median lag was seven days between a CVE being revealed to ultimately being published on the NIST’s NVD. This time lag also significantly differed between vendor announcements and NVD publishing, with … More →

    newswww.helpnetsecurity.comJun 7, 2017, 8:58 PM
  • A newly discovered attack that abuses the Dirty COW vulnerability in the Linux kernel can be leveraged to write malicious code directly into processes, Trend Micro security researchers say.

    newswww.securityweek.comDec 7, 2016, 2:42 PM
  • Google this week released the December 2016 set of monthly patches for the Android platform which resolved a total of 74 vulnerabilities, 11 which were rated Critical severity.

    newswww.securityweek.comDec 6, 2016, 9:41 PM
  • VMware has patched a critical out-of-bounds memory access vulnerability, tracked as CVE-2016-7461, affecting its Workstation and Fusion products. The flaw, that resides in the affects the drag-and-drop function, can be exploited by attackers to execute arbitrary code on the host operating system running Fusion or Workstation. The security vulnerability affects Workstation Player and Pro 12.x, and […]

    newssecurityaffairs.comNov 15, 2016, 6:09 AM
  • VMware informed customers on Sunday that it has patched a critical out-of-bounds memory access vulnerability affecting its Workstation and Fusion products.

    newswww.securityweek.comNov 14, 2016, 1:15 PM
  • Google Washes Dirty COW From AndroidSecurityWeek

    Google’s Android Security Bulletin for November 2016 patched a total of 83 vulnerabilities in the operating system, one of which was the Dirty COW flaw in Linux kernel that was disclosed a few weeks back.

    newswww.securityweek.comNov 8, 2016, 5:10 PM
  • Google on Monday released its November 2016 Android security patches to resolve 83 vulnerabilities in the mobile operating system, 23 of which have been rated Critical.

    newswww.securityweek.comNov 8, 2016, 1:26 PM
  • If you follow cybersecurity news, you may have heard of the latest Linux exploit referenced under CVE-2016-5195, which has been dubbed…

    newswww.malwarebytes.comNov 6, 2016, 5:00 PM
  • The Dirty COW vulnerability in the Linux kernel that was revealed late last month can’t be mitigated with the help of containers, security researchers have discovered.

    newswww.securityweek.comNov 2, 2016, 4:50 PM
  • Cisco announced on Wednesday that it has released software updates for its Email Security Appliances (ESA) to address a total of nine vulnerabilities, including denial-of-service (DoS) and filter bypass issues.

    newswww.securityweek.comOct 27, 2016, 7:49 AM
  • The “Dirty COW” Linux kernel vulnerability that was publicly disclosed last week can be leveraged to achieve root privileges on Android devices, security researchers reveal.

    newswww.securityweek.comOct 25, 2016, 2:38 PM
  • Linux developer Phil Oester has spotted attackers exploiting a Linux kernel zero-day privilege escalation flaw that dates back to 2007, and has raised the alarm. The vulnerability (CVE-2016-5195) has been dubbed Dirty COW by a community-maintained project that took it upon themselves to raise its visibility by appending a name and logo, despite their dislike of “branded” vulnerabilities. Why was it named so? Because, as explained by Red Hat developers, the source of the flaw … More →

    newswww.helpnetsecurity.comOct 21, 2016, 8:11 PM
  • The maintainers of Linux distributions are rushing to patch a privilege escalation vulnerability that’s already being exploited in the wild and poses a serious risk to servers, desktops and other devices that run the OS. The vulnerability, tracked as CVE-2016-5195, has existed in the Linux kernel for the past nine years. This means that many […]

    newswww.csoonline.comOct 21, 2016, 4:10 PM
  • Experts disclosed a new Linux kernel vulnerability dubbed Dirty COW that could be exploited by an unprivileged local attacker to escalate privileges. The security expert Phil Oester discovered in the Linux kernel a new flaw, dubbed ‘Dirty COW‘ that could be exploited by a local attacker to escalate privileges. The name “Dirty COW” is due to the […]

    newssecurityaffairs.comOct 21, 2016, 7:36 AM
  • A new Linux kernel vulnerability disclosed on Wednesday allows an unprivileged local attacker to escalate their privileges on a targeted system. Red Hat said it was aware of an exploit in the wild.

    newswww.securityweek.comOct 20, 2016, 2:38 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence