CVE-2016-5195 — Linux Kernel
CISA KEVRansomwareAs of 2025-11-04, CVE-2016-5195 is a HIGH-severity vulnerability in Linux Kernel, CVSS v3.1 7, EPSS 93.9% (99.8th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03), with a US federal remediation deadline of 2022-03-24, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2016-5195, most recently “SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking)”.
Last updated: 2025-11-04
What is CVE-2016-5195?
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
The record classifies CVE-2016-5195 under weakness class CWE-362. Its CVSS v3 base vector states that the flaw requires local access to the host, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 10 affected-product entries are recorded, across 6 vendors, listed below. The identifier was first published 3594 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 7 — HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS (FIRST)
- 93.9% probability of exploitation in the next 30 days, higher than 99.8% of all scored CVEs
- CISA KEV
- Listed since 2022-03-03, federal remediation deadline 2022-03-24 — used in known ransomware campaigns
- Threadlinqs priority
- 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- Published
- 2016-11-10, last modified 2025-11-04
Is CVE-2016-5195 being exploited?
CISA added CVE-2016-5195 to the Known Exploited Vulnerabilities catalog on 2022-03-03, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2022-03-24 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. It currently carries a trending score of 40 in the Threadlinqs vulnerability feed.
Affected products and versions
- Canonical: Ubuntu Linux
- Linux: Kernel
- Redhat: Enterprise Linux, Enterprise Linux Aus, Enterprise Linux Eus, Enterprise Linux Long Life, Enterprise Linux Tus
- Debian: Linux
- Fedoraproject: Fedora
- Paloaltonetworks: Pan-Os
How to fix CVE-2016-5195
The record marks a vendor fix as available for CVE-2016-5195. Patch reference: https://github.com/torvalds/linux/commit/19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619. Vendor advisory: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619. Because CVE-2016-5195 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2022-03-24. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2016-5195
1 tracked threat in the Threadlinqs corpus references CVE-2016-5195, either in the campaign’s CVE list or as an indicator on the campaign record.
- SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and Financial Sectors (Vibe Hacking) — CRITICAL · 2026-05-12
Sources
Seeded from cveorg and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
- rhn.redhat.com
- exploit-db.com
- access.redhat.com
- bto.bluecoat.com
- h20566.www2.hpe.com
- oracle.com
- exploit-db.com (40839)
- dirtycow.ninja
- exploit-db.com (40847)
- rhn.redhat.com (RHSA 2016 2118)
- rhn.redhat.com (RHSA 2016 2128)
- source.android.com
← all vulnerabilities · Markdown version · Threadlinqs Intelligence