Google Finally Patches 'Dirty COW' Linux Vulnerability With December Android Security Update

Advertisement
By Shekhar Thakran | Updated: 6 December 2016 18:25 IST
Highlights
  • Active exploits of the flaw were discovered two months back
  • Latest security update fixes several critical vulnerabilities
  • The patch for the flaw was earlier expected to come in November

In October, Linux security researcher discovered that a nine-year old Linux kernel flaw (CVE-2016-5195) was witnessing active exploits in the wild. The flaw was dubbed "Dirty COW", an acronym for the duplication technique called copy-on-write, and could potentially give root access of a device to the attacker within a matter of seconds. Now, Google has finally patched the critical flaw on Linux with its latest Android security update, and the patch is available for OEMs to implement on their Android devices.

The latest security update from the search giant, released alongside the Android 7.1.1. Nougat update on Monday, fixes over 50 security flaws including 11 with critical severity - including Dirty Cow. "The exploit in the wild is trivial to execute, never fails and has probably been around for years - the version I obtained was compiled with gcc 4.8," Oester said in October. The bug was initially patched 11 years ago but the fix was later undone in another code commit.

Advertisement

Last month, Google was expected to patch the flaw with its security update for November but the company couldn't patch the flaw at the time. However, Google released a supplemental fix for Pixel and Nexus devices. Kaspersky Lab's Threatpost reported that Samsung also released a fix for its mobile devices. Google had said that the company will introduce the Android-wide patch for Dirty COW in the December Android security update.

As per the dedicated page for this flaw, exploitation of this bug doesn't leave any traces behind. This nature of the flaw makes it even more dangerous as the users will not be made aware even when their security has been compromised.

Advertisement

Apart from this critical flaw, the search giant also patched another critical kernel memory flaw, CVE-2016-4794, which also allows attackers to gain root privileges of users' device. The security update comes with a patch for critical privilege escalation flaws regarding Nvidia's video and camera drivers.

The critical vulnerabilities concerning Qualcomm components was also fixed with company's latest security update.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Best Mobiles Under Rs. 40,000 in India
  2. Motorola Razr Fold Pre-Order Listing Reveal Launch Date, Pricing, Offers
  3. YouTuber Demonstrates Flaw That Allows Money to Be Stolen From Locked iPhone
  4. OnePlus Pad 4 to Launch in India With a 13,380mAh Battery on This Date
  5. Lumio Introduces Vision 9 (2026) and Vision 7 (2026) TVs in India
  6. Apple's OLED Push Could Extend to This iPad Model in 2027
  7. Oppo Find X10 Key Specifications Leak as Find X9 Ultra Launch Nears
  8. Realme Buds T500 Pro Debut in India With Up to 56 Hours Total Battery Life
  9. YouTube Finally Lets You Turn Off Shorts From Your Feed With This Setting
  1. OnePlus Nord CE 6 Lite Appears on Geekbench With Dimensity 7400 Chip, Android 16
  2. Meta’s Planned Facial Recognition Feature for Smart Glasses Faces Opposition From Privacy Orgs
  3. Vivo X300 Ultra Pricing Surfaces Online via Retail Listing in Europe
  4. YouTube's New Option Lets Users Effectively Turn Off Shorts From Their Feed
  5. South Korea Plans Blockchain-Based Payments for Government Spending
  6. Amazon Launches AI Store to Help Users Discover and Shop AI-Powered Devices
  7. Motorola Razr Fold, Lenovo Legion Y70 to Launch Alongside Y900 Tablet During Lenovo's May 19 Event
  8. Apple Tap-to-Pay Vulnerability Demonstrated on Video as YouTuber Steals $10,000 From a Locked iPhone
  9. Adobe’s New Firefly AI Assistant Can Perform Complex Design Tasks With Text Prompts
  10. Crimson Desert Has Sold Over 5 Million Copies, Pearl Abyss Confirms
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.