← לוח פגיעויות

CVE-2016-5195

גבוהה 7.0 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Linux Kernel Race Condition Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

מדדים

CVSS 3.1
7.0 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
83% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-362

מוצרים מושפעים

canonical: ubuntu linux; linux: linux kernel; redhat: enterprise linux; redhat: enterprise linux aus; redhat: enterprise linux eus; redhat: enterprise linux long life; redhat: enterprise linux tus; debian: debian linux; fedoraproject: fedora; paloaltonetworks: pan-os; netapp: cloud backup; netapp: hci storage nodes; netapp: oncommand balance; netapp: oncommand performance manager; netapp: oncommand unified manager for clustered data ontap

קישורים