Linux Kernel Local Privilege Escalation Vulnerability (CVE-2016-5195)

Posted:  May 14th, 2017

 

Description:

 

A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only memory mappings. All the information we have so far is included in this page.

 

The bug has existed since around 2.6.22 (released in 2007) and was fixed on Oct 18, 2016.

 

More Information per Operating System:

 

Please make sure to verify if patched version of your kernel has been released for your Operating system vendors before updating it.

 

Red Hat and CentOS:

https://access.redhat.com/security/vulnerabilities/2706661

 

Debian:

https://security-tracker.debian.org/tracker/CVE-2016-5195

 

Ubuntu:

https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-5195.html

 

We suggest that you subscribe to your operating system notification system at the following URLs:

 

Red Hat - RHSA-announce (http://www.redhat.com/mailman/listinfo/rhsa-announce)

CentOS - CentOS-announce (https://lists.centos.org/mailman/listinfo/centos-announce)

Ubuntu - ubuntu-security-announce (https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce)

Debian - debian-security-announce (https://lists.debian.org/debian-security-announce/)