CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW)…
Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 7.0. EPSS estimates 83.5% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
- State
- PUBLISHED
- Published
- Nov 10, 2016
- Updated
- Nov 4, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAChromeOriginal evidence ↗
Record text: Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Inspect raw assertion
- Field
container- Value
- Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Race Condition Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Race Condition Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 83.52% probability · 99.66th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.835240000000; percentile 0.996610000000
FIRST EPSS · score date Aug 26, 2026 · 99.7th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
Inspect raw assertion
- Field
container- Value
- Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Linux Kernel Race Condition Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Race Condition Vulnerability
83.52% probability · 99.66th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.835240000000; percentile 0.996610000000
Applicability
Cited product scope
Grouped from 7 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
19 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1afb20fa-cb00-4729-ab3a-816454c6d096
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb66db75-2b16-4ebf-9b93-ce49d8086e41
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815d70a8-47d3-459c-a32c-9feaca0659d1
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f59a04-14cf-49e2-9973-645477ea09da
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
772e9557-a371-4664-ae2d-4135aaeb89aa
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c729d5d1-ed95-443a-9f53-5d7c2fd9b80c
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e79ab8dd-c907-4038-a931-1a5a4cfb6a5b
product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exactInspect raw assertions
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 4.8; through excluding 4.8.3
- Match ID
0f5b9915-b0cf-4bda-a889-14834175fde0
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 3.11; through excluding 3.12.66
- Match ID
1e7c6515-c636-45c4-9766-ba26b89f1424
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 4.2; through excluding 4.4.26
- Match ID
905253fb-85d4-4961-8c57-5a1b36741c18
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 3.3; through excluding 3.4.113
- Match ID
9a93f019-b0c0-4723-869e-c715f15e11c9
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 3.13; through excluding 3.16.38
- Match ID
8b1131a4-6eef-4a1f-b706-1a61a471d632
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.6.22; through excluding 3.2.83
- Match ID
6c039170-f1a6-48b9-8a16-aebfd9924804
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 8
- Logic
- OR
- Version bounds
- from including 4.5; through excluding 4.7.9
- Match ID
72401fbf-ceb9-47fd-bac0-efc49b634baa
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 3.5; through excluding 3.10.104
- Match ID
b3b44636-a1ec-47c9-be92-bc761cbb1b7b
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 3.19; through excluding 4.1.35
- Match ID
98821d4f-193b-44ab-8aa9-6f767f25f5e8
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 3.17; through excluding 3.18.44
- Match ID
ebc11daf-1aa0-4b60-a20c-6276bdbf3bc4
product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bfLinked exactInspect raw assertion
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5c2089ee-5d7f-47ec-8ea5-0f69790564c4
product-79e948d8fb7b464f045bf3eb7a73cf70051b9c643393e71fbb96fbc9405127abLinked exactInspect raw assertion
cpe:2.3:a:netapp:hci_storage_nodes:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
855d6a52-f96f-4ca0-a59c-4d42173f22e1
product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267eLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dcbcc5d-c396-47a8-adf4-d3a2c4377fb1
product-0622850d7355e952441687d9dab9a9888a3f7429796731abeb2f2b417c9c9aa0Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_performance_manager:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
212e1878-1b9a-4cb4-a1ce-ead60b867161
product-95e73896397d0cbb5f0e3f0563f3e3efd0e734e7db48b3839de8df88ff44aa32Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_unified_manager_for_clustered_data_ontap:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
392d82a3-21bc-4ce1-a0ac-62a90468f0a5
product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096Linked exactInspect raw assertion
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e7cf3019-975d-40bb-a8a4-894e62bd3797
product-54f6684a68573d65aa78169968c2b2f415c9361813074426c7287d847707d3d1Linked exactInspect raw assertion
cpe:2.3:a:netapp:snapprotect:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f74f467a-0c81-40d9-ba06-40fb8ef02c04
product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8Linked exactInspect raw assertion
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a6e9ef0c-afa8-4f7b-9fdc-1e0f7c26e737
product-612afb736440531327cd224402d663e14e2a3f421cc65267d8acade0f3b99df7Linked exactInspect raw assertions
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 5.1; through excluding 7.0.14
- Match ID
ea10748b-5f96-4a9b-b673-8e7c87f852d4
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 7.1.0; through excluding 7.1.8
- Match ID
214a410f-7160-4e3a-bcce-378ff0d962ea
product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f6ab192-9d7d-4a9a-8995-e53a9de9eafc
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
142ad0dd-4cf3-4d74-9442-459ce3347e3a
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa9b3cc0-df1c-4a86-b2a3-a9d428a5a6e6
product-f3cc34d5623ef33fd690fedee68e310623a54b43b3e4c5cfe2f3da198ffb2184Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_aus:6.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79191794-6151-46e9-aafd-3ec0c05b03b1
cpe:2.3:o:redhat:enterprise_linux_aus:6.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
512237d6-2b4b-4057-8f7c-f11639304028
cpe:2.3:o:redhat:enterprise_linux_aus:6.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d68fb2bb-d103-4ca6-a51e-83db349ddde5
product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_eus:7.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a67a7b7a-998d-4b8c-8831-6e58406565fe
cpe:2.3:o:redhat:enterprise_linux_eus:6.7:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
967ec28a-607f-48f4-ad64-5e3041c768f0
cpe:2.3:o:redhat:enterprise_linux_eus:6.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
319ec0c6-94c5-494a-9c5d-dc5124dfc8e1
product-b76803049f2a654cf7b4724fa7ca2f19fad73487f334bf4f6790889d964bdaedLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_long_life:5.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
84a82ed6-976a-43f1-8820-f5dcb9ddabd9
cpe:2.3:o:redhat:enterprise_linux_long_life:5.9:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5dbe05b8-17f9-4cc7-9579-1c1d57fefd9b
product-97b610ecf2d1a7e04859ffad5ea0fa8cd4db7e96d416e41af80db054927b7678Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_tus:6.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f4de47c-0a23-4bce-bca1-425f7c1450e5
Affected-product evidence
Accepted scope and product mapping
18 canonical links · 1 source-reported links
vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-0622850d7355e952441687d9dab9a9888a3f7429796731abeb2f2b417c9c9aa0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
73fec0f1-9083-4bf3-aa1f-3d1365b718e7vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 10
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
00eeb69d-d700-4bb7-994d-4cafe19c56342cb18ce0-a519-47d3-a3c3-e94a04b09ca8313366e6-58ad-4d24-aa6b-613426305b573b554acc-80db-4895-8a7e-9019f26312da5ddc101d-10d0-473d-9a9b-f0ba6ae944318eff56e0-9d8a-449b-9cc1-9409c7052a8698de3d15-f006-4125-be84-58e1ee1d7811b24d284e-c268-4a6d-b1db-85d37e93ea88c501d3ca-8d65-4fce-ac1d-e2e6256b9bb6d7135135-8a59-445f-bc97-d0583333867dvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8855ef02-9826-42cc-a527-72f206249b10vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
37f43e1e-c846-4222-bef5-074a4b7f73116d91f645-6b71-4170-84d4-f11486ef7282vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
40ea6ebf-bfb2-418c-9e25-e58ca96226e5vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-54f6684a68573d65aa78169968c2b2f415c9361813074426c7287d847707d3d1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9611c266-c71f-455e-94be-7adedd6f58a4vendor-14ea140e990b8248b82877833fdf14fba1a48c6d230b7a5c9157d2a4ac9f719b · product-612afb736440531327cd224402d663e14e2a3f421cc65267d8acade0f3b99df7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01790169-a9c7-450d-afe2-af6016eacdc0d96251ad-64a3-454e-be0f-5dbdd85928c1vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-79e948d8fb7b464f045bf3eb7a73cf70051b9c643393e71fbb96fbc9405127ab
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2f9c50e1-461c-4a6e-8918-b6826517943fvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
887b530d-1bfc-4347-9957-962b5b3dbc0bvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8cdc522d-dc71-4006-a71f-e1df03393e38a543b358-b059-434f-96fc-3d37974c6062c00ab411-1478-43a8-8dc4-decd68c78f07vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-95e73896397d0cbb5f0e3f0563f3e3efd0e734e7db48b3839de8df88ff44aa32
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0cb1efc2-4db1-4716-8af7-9fc08590259cvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-97b610ecf2d1a7e04859ffad5ea0fa8cd4db7e96d416e41af80db054927b7678
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2014446d-6b24-45a4-a337-71da1eb38d6dvendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3c8f2dfb-da40-4d2e-80ac-6bdaf07cf7d644b45775-0742-47e9-a810-4475d974fb08bb0ae338-9d68-4ee6-9eeb-d15d25b7f5f8f1577d7e-dc06-41e0-a45f-c9a6eae456b9vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1981a145-e7c4-49f3-a531-9b2f2843700evendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b76803049f2a654cf7b4724fa7ca2f19fad73487f334bf4f6790889d964bdaed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
807c592e-e1a4-4a44-9655-6c6113501076b07091c4-5067-4b82-b7d1-0d1cb8b45611vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2ff65722-637e-4023-b3dd-2b98b6c0d56a6d84dad8-3936-4351-817e-0f1359d68b876e262fa3-db58-4210-bb63-a067d7f1a176vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
669c11e5-ba05-4b54-adca-eeb0dc37ffe27386eee9-2bf7-46ad-972d-930d2b58878b74da5a07-7ccd-4c4d-a599-762e16f24670vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-f3cc34d5623ef33fd690fedee68e310623a54b43b3e4c5cfe2f3da198ffb2184
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
004b170b-e0c2-4519-b76e-5f2429f331490a0809f3-22f8-4ab4-9557-8c1db02a42f98c7fa023-86fc-4a68-8ab5-cb1cb9669f52Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
698cd385-3a8a-4bc5-9076-6da450a3bad4Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 7.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.