CVE-2016-6516 is a race condition vulnerability in the ioctl_file_dedupe_range function within fs/ioctl.c of the Linux kernel up to version 4.7. The vulnerability arises from a double fetch issue, where a user-controlled count value is fetched multiple times without proper synchronization, allowing a local attacker to manipulate the value between fetches. This can result in a heap-based buffer overflow or potentially privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains multiple C source files and supporting documentation for exploiting the double-fetch vulnerability (CVE-2016-6516) in the Linux kernel's file deduplication ioctl (FIDEDUPERANGE). The main exploit logic is found in 'exploit.c', which is an annotated and optimized version of the original proof-of-concept by Scott Bauer (whose code is in 'Scott Bauer/doublefetch.c'). The exploit works by creating a race condition between two threads: one thread repeatedly changes the 'dest_count' field of a 'file_dedupe_range' structure, while the other triggers the FIDEDUPERANGE ioctl. This can cause the kernel to fetch inconsistent values, potentially leading to memory corruption or privilege escalation. The repository also includes kernel source files ('ioctl.c', 'read_write.c') for reference, and a 'cmd.txt' file with instructions for setting up a vulnerable kernel environment. The exploit is a proof-of-concept and does not provide a direct shell or privilege escalation payload, but demonstrates the vulnerability's exploitability. The attack vector is local, requiring the attacker to execute code on the target system. Fingerprintable endpoints include the file paths used for the deduplication operation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.