> Source: [sk114161](https://support.checkpoint.com/results/sk/sk114161)

# sk114161 - Check Point response to CVE-2016-5195 (Dirty Cow)

| Property | Value |
|----------|-------|
| Solution ID | sk114161 |
| Date Created | 2016-10-26 |
| Last Modified | 2022-08-08 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |
| OS | Gaia |

## Symptoms

- A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only memory mappings. An unprivileged, local user could use this flaw to gain write access to otherwise read-only memory mappings and thus increase their privileges on the system.  
This issue was assigned [CVE-2016-5195](https://access.redhat.com/security/cve/cve-2016-5195).

## Solution

This vulnerability is a local privilege escalation bug that affects only kernel versions 2.6.22 and higher.

Check Point Gaia OS and SecurePlatform OS are based on hardened kernel versions 2.6.18 (or lower).

This vulnerability is *irrelevant* to Check Point operating systems, because all users on Check Point operating systems are system administrators (and only they should have local access)

Check Point strives to make the customers' systems as secure as possible.  
Therefore, the official resolution (published by RHEL/Linux mainstream) was implemented and is included in:

* [Check Point R80.10](http://supportcontent.checkpoint.com/solutions?id=sk111841)
* [Jumbo Hotfix Accumulator for R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106162) - since *Take_198*
* [Jumbo Hotfix Accumulator for R77.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101975) - since *Take_200*

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) can supply a **Hotfix** .  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Gaia / SecurePlatform OS machine involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
