Android November Security Update Doesn't Contain Fix for 'Dirty COW' Linux Flaw

Advertisement
By Shekhar Thakran | Updated: 9 November 2016 18:42 IST
Highlights
  • November security update fixes 15 critical vulnerabilities
  • Flaw was highlighted last month by Phil Oester
  • Doesn't leave any traces of exploitation behind
Android November Security Update Doesn't Contain Fix for 'Dirty COW' Linux Flaw

Last month, Linux security researcher Phil Oester discovered that a nine-year-old Linux kernel flaw (CVE-2016-5195) dubbed 'Dirty COW' is seeing active exploits in the wild. Google was expected to patch this flaw - after all, Android uses the Linux kernel - with its latest security update but as it turns out, the search giant has left out this dated flaw with its security update for November.

The November Android security update fixes 15 critical vulnerabilities associated with the platform, but surprisingly, this vulnerability discovered by Oester has still not found a fix. The extent of the danger posed by this vulnerability can be understood from the fact that Oester claims that on exploitation, it can give root access of a device to the attacker within five seconds.

"The exploit in the wild is trivial to execute, never fails and has probably been around for years - the version I obtained was compiled with gcc 4.8," Oester said last month. The bug was initially patched 11 years ago but the fix was later undone in another code commit.

Kaspersky Lab's Threatpost reports that while the main Android security update for the month of November did not contain a fix for the Dirty COW flaw, Google released a supplemental fix for Pixel and Nexus devices. It adds that Samsung also released a fix for its mobile devices. Google will introduce the Android-wide patch for Dirty COW in the December Android security update, the company told Threatpost.

Advertisement

As per the dedicated page for this flaw, exploitation of this bug doesn't leave any traces behind. This nature of the flaw makes it even more dangerous as the users will not be made aware even when their security has been compromised.

Further details about the latest Android security update can be found over here.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Announces iOS 26 With Liquid Glass Design, These New Features
  2. iQOO 13 and More Available With Discounts During iQOO 5th Anniversary Sale
  3. Poco F7 India Launch Teased; Flipkart Availability Confirmed
  4. Everything We Know About the Vivo T4 Ultra Ahead of Its June 11 Launch
  5. Apple Intelligence Will Now Provide Live Translations on Your iPhone
  6. Lava Storm Play 5G, Storm Lite 5G Design Teased; India Launch Date Set
  7. Realme Narzo 80 Lite 5G India Launch, Price Range and Key Features Teased
  8. WWDC 2025 Highlights: Apple Unveils iOS 26, macOS 26 and Liquid Glass UI
  9. Tecno Pova 7 Ultra 5G Tipped to Offer Magnetic Wireless Charging
  10. Apple Unveils iPadOS 26 With New Windowing System at WWDC 2025
  1. WWDC 2025: Apple Unveils iPadOS 26 With New Windowing System, Liquid Glass UI, and More
  2. WWDC 2025: macOS Tahoe 26 Unveiled With New Design, Continuity Features and Big Update to Spotlight
  3. WWDC 2025: Apple Announces iOS 26 With New Liquid Glass Design, Apple Intelligence Enhancements and More
  4. WWDC 2025: Apple Intelligence Models Expanded to Developers, Live Translation Feature Unveiled
  5. Xbox Chief Phil Spencer Hints at 'Return' of Halo: Combat Evolved Next Year
  6. Vivo X Fold 5 Design Teased; Confirmed to Feature 8T LTPO Panels, Meet IP5X and IPX9+ Certifications
  7. Oppo K13x 5G Price Range in India Tipped; Alleged Retail Box Suggests Flat Display
  8. WWDC 2025: Apple Faces AI, Regulatory Challenges As it Woos Developers at Annual Conference
  9. WazirX Parent Zettai Urges Singapore Court to Review WazirX Restructuring, Extend Moratorium
  10. AI+ Smartwatch With Built-in TWS Tipped to Launch in June; Retail Box Image Leaked
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.