Database/Kernel, userspace & hypervisor
Linux kernel (mm, COW): Dirty COW: privilege escalation via MAP_PRIVATE COW breakage
CVSS 7.8CVE-2016-5195Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Dirty COW: privilege escalation via MAP_PRIVATE COW breakage; classic container-escape-to-root primitive [KEV]
Who can reach it
Any tenant process in a container
What to do
Livepatchable (kpatch/Ksplice/KernelCare shipped livepatches); otherwise drain + reboot. Any node still vulnerable is EOL and should be reimaged
References
Related entries
- Linux kernel VFIO drivers/vfio/pci/vfio_pci.c - VFIO_DEVICE_SET_IRQS ioctl: A state-machine confusion inCVE-2016-9083 · Linux kernel VFIO drivers/vfio/pci/vfio_pci.c - VFIO_DEVICE_SET_IRQS ioctlHigh
- Linux kernel VFIO drivers/vfio/pci/vfio_pci_intrs.c - MSI/MSI-X allocation: Sibling of CVE-2016-9083 in the sameCVE-2016-9084 · Linux kernel VFIO drivers/vfio/pci/vfio_pci_intrs.c - MSI/MSI-X allocationHigh
- Linux kernel (ELF loader): PIE stack buffer corruption, local rootCVE-2017-1000253 · Linux kernel (ELF loader)High
- Linux i915 GPU kernel driver (execbuffer2 ioctl): The execbuffer2 ioctl accepted a userspace-supplied address withoutCVE-2018-20669 · Linux i915 GPU kernel driver (execbuffer2 ioctl)High
- Intel i915 graphics kernel-mode driver for Linux (< 5.0): Insufficient input validation in the i915 kernel-mode driverCVE-2019-11085 · Intel i915 graphics kernel-mode driver for Linux (< 5.0)High
- Linux kernel (ptrace): Broken permission and object lifetime handling for PTRACE_TRACEME, local rootCVE-2019-13272 · Linux kernel (ptrace)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.