Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 83.5%; technical severity is CVSS 7.0.
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Who should care
- Teams operating Ubuntu Linux, Debian Linux, Fedora +16 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Debian Linux, Fedora +16 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security patch Cpujul2018 4258247
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
- Oracle Security patch Cpujul2018 4258247Oracle · Vendor sourceVerification pending ↗
- Juniper Networks Security patchJuniper Networks · Vendor sourceVerification pending ↗
- Juniper Networks Security patchJuniper Networks · Vendor sourceVerification pending ↗
- Juniper Networks Security patchJuniper Networks · Vendor sourceVerification pending ↗
- HPE Security patch DocDisplayHPE · Vendor sourceVerification pending ↗
- HPE Security patch DocDisplayHPE · Vendor sourceVerification pending ↗
Upgrade
- Kernel Security release notes ChangeLog 4.8.3KernelVerification pending ↗
- Lists Fedoraproject Security release notes E7M62SRP6CZLJ4ZXCRZKV4WPLQBSR7DTLists FedoraprojectVerification pending ↗
- Lists Fedoraproject Security release notes NWMDLBWMGZKFHMRJ7QUQVCERP5QHDB6WLists FedoraprojectVerification pending ↗
- Lists Fedoraproject Security release notes W3APRVDVPDBXLH4DC5UKZVCR742MJIM3Lists FedoraprojectVerification pending ↗
Advisory
- Cisco Security advisory Cisco Sa 20161026 LinuxCisco · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 3696Debian · Vendor sourceVerification pending ↗
- Red Hat Security advisory CVE-2016-5195Red Hat · Vendor sourceVerification pending ↗
- Red Hat Security advisory 2706661Red Hat · Vendor sourceVerification pending ↗
- Cisco Security advisory Cisco Sa 20181107 VcsdCisco · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-362
- Affected versions
- Canonical Ubuntu Linux (Version 12.04 | Version 14.04 | Version 16.04 | Version 16.10); Debian Debian Linux (Version 7.0 | Version 8.0); Fedoraproject Fedora (Version 23 | Version 24 | Version 25); Linux Kernel; Linux Linux Kernel (Start Including 2.6.22, End Excluding 3.2.83 | Start Including 3.3, End Excluding 3.4.113 | Start Including 3.5, End Excluding 3.10.104 | Start Including 3.11, End Excluding 3.12.66); Netapp Cloud Backup (Version -); Netapp Hci Storage Nodes (Version -); Netapp Oncommand Balance (Version -)
- Fixed versions
- Linux Linux Kernel (Fixed from 3.2.83, 3.4.113, 3.10.104, 3.12.66, 3.16.38, 3.18.44, 4.1.35, 4.4.26, 4.7.9, 4.8.3); Paloaltonetworks Pan-os (Fixed from 7.0.14, 7.1.8)
- Published
- 10 November 2016
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 83.5%
- Signal calculated at 80
External references
- Red Hat Third-party advisory RHSA 2016 2098
- Red Hat Third-party advisory RHSA 2016 2105
- Red Hat Third-party advisory RHSA 2016 2106
- Red Hat Third-party advisory RHSA 2016 2107
- Red Hat Third-party advisory RHSA 2016 2110
- Red Hat Third-party advisory RHSA 2016 2118
- Red Hat Third-party advisory RHSA 2016 2120
- Red Hat Third-party advisory RHSA 2016 2124
- Red Hat Third-party advisory RHSA 2016 2126
- Red Hat Third-party advisory RHSA 2016 2127
- Red Hat Third-party advisory RHSA 2016 2128
- Red Hat Third-party advisory RHSA 2016 2132