KernelScan.io

HIGH CISA KEV Public exploit

mm DirtyCOW Race

CVE-2016-5195

CVSS 7.0 / 10.0 NVD

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

02

Engine v0.6.0

Risk summary

Dirty COW is a widely exploited local privilege escalation affecting virtually all Linux kernels for over a decade. Any local unprivileged user can race a memory advisory call against the kernel's get-user-pages path to write to read-only file-backed mappings, enabling modification of setuid binaries, /etc/passwd, or other privileged files. The fix replaces a racy flag-clearing sequence with a dedicated COW flag validated by the PTE dirty bit, closing the write window. Exploitability depends on whether unprivileged local code execution is permitted on the system.

Affectedmm/gup.c

Vulnerability analysis

The kernel's get-user-pages path handles copy-on-write by clearing the write-intent flag after a COW fault, intending to allow a follow-up read of the newly copied page. However, if another thread concurrently invalidates the page table entry (e.g., via madvise), the next GUP iteration sees the flag already cleared and proceeds to pin the original read-only page for writing—bypassing COW entirely and granting write access to a mapping the process should only be able to read. This lets any local unprivileged user modify read-only file-backed pages (such as setuid binaries or system configuration files), yielding reliable privilege escalation. The fix replaces the flag-clearing trick with a dedicated internal COW flag and a helper that only permits the follow-up write when the page table entry is still dirty, closing the race window. The attack surface is purely local: any unprivileged user with code execution on the target system can trigger it; no special hardware, network access, or elevated privileges are required.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
mainline—4.9-rc219be0eaffa3a
4.8—4.8.3—
3.10—3.10.1049691eac5593f