Securitylab•August 25, 2026•🇷🇺Translated from Russian

Dirty COW CVE-2016-5195: How a 2016 Linux Kernel Race Condition Still Enables Privilege Escalation in Embedded Systems

The 2016 discovery of CVE-2016-5195, widely known as Dirty COW, revealed a race condition in the Linux kernel’s copy-on-write mechanism. The flaw enabled a local attacker to modify memory pages that should have remained read-only, providing a primitive for writing to protected files or memory regions.

Although the vulnerability was fixed in October 2016 for mainstream distributions, many embedded devices continue to run unpatched kernels for years. Routers, IP cameras, industrial controllers, and similar hardware often ship with vendor firmware that is rarely updated, leaving the original bug intact.

What Dirty COW Actually Allows

Dirty COW does not grant root privileges directly. It supplies a write primitive that can alter files such as /etc/passwd or overwrite code in memory-mapped regions. Attackers must then chain this primitive with additional steps, such as adding a root user entry or modifying a SUID binary, to achieve privilege escalation.

Public proof-of-concept code repeatedly triggers the race by writing through /proc/self/mem while calling madvise(..., MADV_DONTNEED). Correct timing causes the kernel to drop the original copy-on-write page, allowing the attacker’s data to persist in the shared mapping.

Why Ready-Made Exploits Often Fail

Many public Dirty COW exploits assume a full GNU userland with /bin/sh and conventional login utilities. On embedded systems that use BusyBox, these assumptions break. The single BusyBox binary may lack the expected applet, the required symbolic link may be absent, or the arguments passed to execve may not match the applet’s expectations.

Another common target is vDSO, a small kernel-provided library mapped into every process address space. Because vDSO exists only in memory and not as a file on disk, overwriting its functions requires precise knowledge of the architecture, the exported symbols, and the exact function chosen by the exploit. Payloads must also be written in the correct instruction set and respect the target ABI.

Practical Checks Before Exploitation

  • Kernel version, build date, and presence of the Dirty COW patch
  • Processor architecture, endianness, and enabled mitigations
  • Available BusyBox applets and presence of login or su mechanisms
  • Existence and contents of SUID binaries
  • Presence and exported symbols of vDSO in process memory maps
  • Compatibility of the chosen payload with the system’s libraries and shell environment

Exploitation attempts should be performed only on isolated test systems with rollback capability, as race-condition bugs can corrupt data or crash the target.

The article concludes by pointing readers to the free “White Hacker” course on the CyberED platform, where the practical lab “Strange And Dirty” requires participants to adapt a Dirty COW exploit to a minimal BusyBox environment and complete the privilege-escalation chain.

Related articles

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.

Security NEXT•Vulnerabilities & Exploits

Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings

Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.

Security NEXT•Vulnerabilities & Exploits

Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw

Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.