Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5195

95
FAUCET Score

CVE-2016-5195, known as "Dirty COW," is a race condition in the Linux kernel (versions 2.x through 4.x before 4.8.3) that allows local users to gain privileges by exploiting a copy-on-write (COW) feature to write to read-only memory. This vulnerability affects numerous Linux distributions including Canonical, Debian, Fedora, and Red Hat. With a CVSS score of 7.0 (High), it has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with multiple public exploit codes available on ExploitDB, and has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
16.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*
>= 2.6.22, < 3.2.83CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
83.01%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Mar 3, 2022
ExploitDB: EDB-40839 · Nov 28, 2016
This CVE's current EPSS score of 0.8301 is in the 100th percentile among its peer group of 1,516 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

github_advisorypatch availablevia nvd_reference
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Long LifeFixed in: kernel-0:2.6.18-348.32.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-642.6.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.68.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Advanced Update SupportFixed in: kernel-0:2.6.32-358.75.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: kernel-0:2.6.32-431.75.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Telco Extended Update SupportFixed in: kernel-0:2.6.32-431.75.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-416.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.7 Extended Update SupportFixed in: kernel-0:2.6.32-573.35.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-327.36.3.rt56.238.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-327.36.3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-aarch64-0:4.5.0-15.2.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.1 Extended Update SupportFixed in: kernel-0:3.10.0-229.42.2.ael7b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-327.rt56.198.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Extended Update SupportFixed in: kernel-0:2.6.32-504.54.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 Long LifeFixed in: kernel-0:2.6.18-238.57.1.el5
View patch

Vendor Advisories (2)

linuxCVE-2016-5195HIGH

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

Nov 10, 2016
redhatCVE-2016-5195Important

kernel: mm: privilege escalation via MAP_PRIVATE COW breakage

Oct 19, 2016

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
seclists.org / fulldisclosure/2024/Aug/35
Mailing ListThird Party Advisory
fortiguard.com / advisory/FG-IR-16-063
Third Party Advisory
git.kernel.org / cgit/linux/kernel/git/torvalds/linux.git/commit
Issue TrackingPatchVendor Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-10/msg00034.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00035.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00036.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00038.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00039.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00040.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00045.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00048.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00049.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00050.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00051.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00052.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00053.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00054.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00055.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00056.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00057.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00058.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00063.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00064.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00065.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00066.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00067.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-10/msg00072.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-12/msg00033.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2016-12/msg00100.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2020-04/msg00041.html
Third Party Advisory
packetstormsecurity.com / files/139277/Kernel-Live-Patch-Security-Notice-LSN-0012-1.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/139286/DirtyCow-Linux-Kernel-Race-Condition.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/139287/DirtyCow-Local-Root-Proof-Of-Concept.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/139922/Linux-Kernel-Dirty-COW-PTRACE_POKEDATA-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/139923/Linux-Kernel-Dirty-COW-PTRACE_POKEDATA-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/142151/Kernel-Live-Patch-Security-Notice-LSN-0021-1.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2016-2098.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2105.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2106.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2107.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2110.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2118.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2120.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2124.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2126.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2127.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2128.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2132.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2133.html
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0372
Broken LinkThird Party Advisory
access.redhat.com / security/cve/cve-2016-5195
Third Party Advisory
access.redhat.com / security/vulnerabilities/2706661
Third Party Advisory
bto.bluecoat.com / security-advisory/sa134
Permissions RequiredThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
ExploitIssue Tracking
bugzilla.suse.com / show_bug.cgi
Issue Tracking
dirtycow.ninja
Third Party Advisory
github.com / dirtycow/dirtycow.github.io/wiki/PoCs
Third Party Advisory
github.com / dirtycow/dirtycow.github.io/wiki/VulnerabilityDetails
ExploitThird Party Advisory
github.com / torvalds/linux/commit/19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619
Issue TrackingPatch
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
help.ecostruxureit.com / display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
Broken LinkThird Party Advisory
kc.mcafee.com / corporate/index
Broken LinkThird Party Advisory
kc.mcafee.com / corporate/index
Broken LinkThird Party Advisory
kc.mcafee.com / corporate/index
Broken LinkThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/E7M62SRP6CZLJ4ZXCRZKV4WPLQBSR7DT
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NWMDLBWMGZKFHMRJ7QUQVCERP5QHDB6W
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/W3APRVDVPDBXLH4DC5UKZVCR742MJIM3
Release Notes
people.canonical.com / ~ubuntu-security/cve/2016/CVE-2016-5195.html
Third Party Advisory
security.netapp.com / advisory/ntap-20161025-0001
Third Party Advisory
security.paloaltonetworks.com / CVE-2016-5195
Third Party Advisory
security-tracker.debian.org / tracker/CVE-2016-5195
Issue TrackingThird Party Advisory
source.android.com / security/bulletin/2016-11-01.html
Third Party Advisory
source.android.com / security/bulletin/2016-12-01.html
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-vcsd
Third Party Advisory
arista.com / en/support/advisories-notices/security-advisories/1753-security-advisory-0026
Third Party Advisory
exploit-db.com / exploits/40611
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/40616
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/40839
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/40847
Third Party AdvisoryVDB Entry
kb.cert.org / vuls/id/243144
Third Party AdvisoryUS Government Resource
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-linux
Third Party Advisory
debian.org / security/2016/dsa-3696
Third Party Advisory
huawei.com / en/psirt/security-advisories/huawei-sa-20161207-01-dirtycow-en
Third Party Advisory
kernel.org / pub/linux/kernel/v4.x/ChangeLog-4.8.3
Release Notes
openwall.com / lists/oss-security/2016/10/21/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2016/10/26/7
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2016/10/27/13
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2016/10/30/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2016/11/03/7
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/03/07/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/08/08/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/08/08/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/08/08/7
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/08/08/8
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/08/09/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/08/15/1
Mailing ListThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2018-4258247.html
PatchThird Party Advisory
securityfocus.com / archive/1/539611/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/540252/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/540344/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/540736/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/archive/1/539611/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/archive/1/540252/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/archive/1/540344/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / archive/1/archive/1/540736/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/93793
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1037078
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-3104-1
Third Party Advisory
ubuntu.com / usn/USN-3104-2
Third Party Advisory
ubuntu.com / usn/USN-3105-1
Third Party Advisory
ubuntu.com / usn/USN-3105-2
Third Party Advisory
ubuntu.com / usn/USN-3106-1
Third Party Advisory
ubuntu.com / usn/USN-3106-2
Third Party Advisory
ubuntu.com / usn/USN-3106-3
Third Party Advisory
ubuntu.com / usn/USN-3106-4
Third Party Advisory
ubuntu.com / usn/USN-3107-1
Third Party Advisory
ubuntu.com / usn/USN-3107-2
Third Party Advisory