{
  "id": "CVE-2016-5195",
  "url": "https://spydr.io/cve/CVE-2016-5195",
  "published": "2016-11-10T21:59:00.197Z",
  "modified": "2026-06-17T00:48:56.647Z",
  "score": 7,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.83524,
  "epss_percentile": 0.9968,
  "exploited": true,
  "kev": {
    "added": "2022-03-03",
    "due": "2022-03-24",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Linux Kernel Race Condition Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2016-5195"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "canonical",
    "linux",
    "redhat",
    "debian",
    "fedoraproject",
    "paloaltonetworks",
    "netapp"
  ],
  "products": [
    "canonical ubuntu linux",
    "linux kernel",
    "redhat enterprise linux",
    "redhat enterprise linux aus",
    "redhat enterprise linux eus",
    "redhat enterprise linux long life",
    "redhat enterprise linux tus",
    "debian linux",
    "fedoraproject fedora",
    "paloaltonetworks pan-os",
    "netapp cloud backup",
    "netapp hci storage nodes",
    "netapp oncommand balance",
    "netapp oncommand performance manager",
    "netapp oncommand unified manager for clustered data ontap",
    "netapp ontap select deploy administration utility",
    "netapp snapprotect",
    "netapp solidfire"
  ],
  "cwes": [
    "CWE-362"
  ],
  "description": "Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka \"Dirty COW.\"",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://fortiguard.com/advisory/FG-IR-16-063",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10770",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10774",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10807",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00034.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00035.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00036.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00038.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00039.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00040.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00045.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00049.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00050.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00051.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00052.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00053.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00054.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00055.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00056.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00057.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00058.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00064.html",
      "tags": [
        "Mailing List"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2016-5195",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
