Android November Security Update Doesn't Contain Fix for 'Dirty COW' Linux Flaw

Advertisement
By Shekhar Thakran | Updated: 9 November 2016 18:42 IST
Highlights
  • November security update fixes 15 critical vulnerabilities
  • Flaw was highlighted last month by Phil Oester
  • Doesn't leave any traces of exploitation behind

Last month, Linux security researcher Phil Oester discovered that a nine-year-old Linux kernel flaw (CVE-2016-5195) dubbed 'Dirty COW' is seeing active exploits in the wild. Google was expected to patch this flaw - after all, Android uses the Linux kernel - with its latest security update but as it turns out, the search giant has left out this dated flaw with its security update for November.

The November Android security update fixes 15 critical vulnerabilities associated with the platform, but surprisingly, this vulnerability discovered by Oester has still not found a fix. The extent of the danger posed by this vulnerability can be understood from the fact that Oester claims that on exploitation, it can give root access of a device to the attacker within five seconds.

"The exploit in the wild is trivial to execute, never fails and has probably been around for years - the version I obtained was compiled with gcc 4.8," Oester said last month. The bug was initially patched 11 years ago but the fix was later undone in another code commit.

Advertisement

Kaspersky Lab's Threatpost reports that while the main Android security update for the month of November did not contain a fix for the Dirty COW flaw, Google released a supplemental fix for Pixel and Nexus devices. It adds that Samsung also released a fix for its mobile devices. Google will introduce the Android-wide patch for Dirty COW in the December Android security update, the company told Threatpost.

Advertisement

As per the dedicated page for this flaw, exploitation of this bug doesn't leave any traces behind. This nature of the flaw makes it even more dangerous as the users will not be made aware even when their security has been compromised.

Further details about the latest Android security update can be found over here.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo 90 Series 5G India Launch Announced
  2. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  3. Be Dune Teen OTT Release: When, Where to Watch the Marathi Comedy Drama
  4. New Shortcut Lets Scientists Run Complex Quantum Models on a Laptop
  5. Glaciers Speed Up in Summer and Slow in Winter, New Global Map Reveals
  1. Starlink Subscription Price in India Revealed as Elon Musk-Led Firm Prepares for Imminent Launch
  2. Google Releases Gemini 3 Deep Think Model to Its Most Expensive Subscription Tier
  3. Meta’s Phoenix Mixed Reality Smart Glasses Reportedly Delayed; Could Finally Launch in 2027
  4. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  5. OpenAI Clarifies It Isn’t Testing Ads on ChatGPT Despite User Claims
  6. Realme Narzo 90 Series 5G India Launch Announced; to Go on Sale via Amazon
  7. New Shortcut Lets Scientists Run Complex Quantum Models on a Laptop
  8. Glaciers Speed Up in Summer and Slow in Winter, New Global Map Reveals
  9. Be Dune Teen OTT Release: When, Where to Watch the Marathi Comedy Drama Series
  10. Four More Shots Please Season 4 OTT Release: Where to Watch the Final Chapter of the Web Series
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.