Linux Exploit in the Wild; Gives Any User Root Access in Less Than Five Seconds

Advertisement
By Shekhar Thakran | Updated: 24 October 2016 18:08 IST
Highlights
  • Kernel flaw estimated to be around since 2007
  • The exploit is trivial to execute and never fails
  • Exploit doesn't leave any traces behind

In modern world, user security is a crucial factor when it comes to deciding on a service, technology or an operating system. This is precisely why various companies go the distance to convince potential customers that they provide the most secure platform. The venerable open-source operating system, Linux, has often been under the scanner for vulnerabilities, and now a security researcher has discovered a nine-year old flaw is seeing active exploits in the wild. The local privilege escalation vulnerability is a kernel flaw can give any user write access that could lead to complete root access.

Phil Oester, the Linux security researcher who initially discovered the flaw (CVE-2016-5195), told V3 that organisations and individuals have been asked to patch the Linux servers in order to avoid this bug, which has been dubbed as 'Dirty COW', an acronym for the duplication technique called copy-on-write.

"The exploit in the wild is trivial to execute, never fails and has probably been around for years - the version I obtained was compiled with gcc 4.8," Oester was quoted as saying in the report. In an email to Ars Technica, he added, "Any user can become root in < 5 seconds in my testing, very reliably. Scary stuff... The vulnerability is easiest exploited with local access to a system such as shell accounts. Less trivially, any web server/application vulnerability which allows the attacker to upload a file to the impacted system and execute it also works."

Advertisement

The bug was first patched 11 years ago, admittedly 'badly', by Linus Torvalds himself. But the fox was later undone in another code commit, Torvalds explains in his notes for the latest patch to the Linux kernel. Oester estimates the bug has existed since 2007, and adds that the flaw is currently being exploited maliciously - something he discovered with "rolling packet captures".

Advertisement

"As to who is being targeted, anyone running Linux on a web facing server is vulnerable," Oester adds. Ars Technica points out flaw is in section of the Linux kernel that's part of "virtually every distribution of the open-source OS released for almost a decade." Distributors are now releases patches for their versions of Linux.

"A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only memory mappings. An unprivileged, local user could use this flaw to gain write access to otherwise read-only memory mappings and thus increase their privileges on the system," Red Hat said in a note regarding the kernel flaw.

Advertisement

Even though the attack complexity is a problem, because they can target different layers, Oester suggested that an antivirus software can be programmed to detect - but not block - an attack. As per the dedicated page for this flaw, exploitation of this bug doesn't leave any traces behind.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Unveils Signature Phone With Four 50-Megapixel Cameras
  2. Redmi Pad 2 Pro 5G With 12,000mAh Battery Arrives in India: See Price
  3. Motorola Unveils Razr Fold as its First Book-Style Foldable at CES
  4. Realme 16 Pro Series With 7,000mAh Battery Debuts in India: See Price
  5. Redmi Note 15 5G First Impressions
  6. CES 2026: Motorola Enters the Wearable AI Race With Project Maxwell
  7. iQOO Z11 Key Specifications Confirmed Ahead of Imminent Launch in China
  8. Vivo Y50s 5G, Vivo Y50e 5G Launched With 6,000mAh Battery: Price, Features
  9. Vivo X200T Said to Launch in India With 'Aggressive' Pricing
  10. Realme 16 Pro+, Realme 16 Pro Review: A New Dawn for Realme
  1. OnePlus Turbo 6 Series Confirmed to Feature BOE Displays With Up to 165Hz Refresh Rate
  2. Lenovo Legion Go 2 SteamOS Version Revealed at CES 2026, Will Be Available From June 2026
  3. Motorola Unveils Unified AI Platform and AI Pin-Styled Wearable Device Prototype at CES 2026
  4. iQOO Z11 Turbo Battery, Charging Details Confirmed; Tipster Leaks Camera Specifications
  5. CES 2026: Eureka Z50, E10 Evo Plus Robot Vacuum Cleaners Launched, FloorShine 890 Tags Along
  6. Motorola Unveils Signature Phone With Snapdragon 8 Gen 5 Chip and 50-Megapixel Sony LYTIA Cameras: Price, Specifications
  7. CES 2026: Motorola Razr Fold Announced With 2K LTPO Inner Display, 50-Megapixel Triple Cameras
  8. Self-Driving Cars Could Prevent Over 1 Million Road Injuries Across the U.S. by 2035
  9. Astronomers Measure Mass and Distance of a Rogue Planet for the First Time in History
  10. The Rip OTT Release Date: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.