security flaw
Published Sep 1, 2004
7.2
HIGHCVSS 2.0
EPSS 2.43%
Description
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.
Affected products
No data.
Configuration 1
- 2.4.20-8
- 2.4.20-8
- 2.4.20-8
- 2.4.20-8
- 2.4.20-8
Configuration 2
- 2.4.20-8
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.2.9
- 2.2.10
- 2.2.11
- 2.2.12
- 2.2.13
- 2.2.14
- 2.2.15
- 2.2.15
- 2.2.15_pre20
- 2.2.16
- 2.2.16
- 2.2.17
- 2.2.18
- 2.2.19
- 2.2.20
- 2.2.21
- 2.2.22
- 2.2.23
- 2.2.24
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 2.4.8
- 2.4.9
- 2.4.10
- 2.4.11
- 2.4.12
- 2.4.13
- 2.4.14
- 2.4.15
- 2.4.16
- 2.4.17
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.18
- 2.4.19
- 2.4.19
- 2.4.19
- 2.4.19
- 2.4.19
- 2.4.19
- 2.4.19
- 2.4.20
- 2.4.21
- 2.4.21
- 2.4.21
- 2.4.21
- 2.4.22
- 2.4.23
- 2.4.23
- 2.4.24
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.0
- 2.6.1
- 2.6.1
- 2.6.2
- 2.6_test9_cvs
- 1.0
- 1.5
- 2.0
No data.
Red Hat Enterprise Linux 3
kernel-0:2.4.21-9.0.1.EL
Fixed · RHSA-2004:066
Red Hat Enterprise Linux 3
s390utils-2:1.2.4-3
Fixed · RHSA-2004:066
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2004:069
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2004:106
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2004:069
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2004:069
Red Hat Linux 9
n/a
Fixed · RHSA-2004:065
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2004:106
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-9.0.1.EL | Fixed | RHSA-2004:066 |
| Red Hat Enterprise Linux 3 | s390utils-2:1.2.4-3 | Fixed | RHSA-2004:066 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2004:069 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2004:106 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2004:069 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2004:069 |
| Red Hat Linux 9 | n/a | Fixed | RHSA-2004:065 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2004:106 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.43% (0.02434) | 83.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.43% (0.02434) | 82.08th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.11% (0.00108) | 26.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 0.34th | v3 (v2023.03.01) |
| Mar 9, 2024 | 0.04% (0.00042) | 0.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00043) | 7.42th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.00% (0.04005) | 85.96th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.00% (0.04005) | 84.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.00% (0.04005) | 67.83th | v2 (v2022.01.01) |
No CWE recorded.
References (40)
- http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html mailing-listx_refsource_VULNWATCH
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000820 vendor-advisoryx_refsource_CONECTIVA
- http://fedoranews.org/updates/FEDORA-2004-079.shtml vendor-advisoryx_refsource_FEDORA
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015 vendor-advisoryx_refsource_MANDRAKE
- http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt x_refsource_MISC
- http://marc.info/?l=bugtraq&m=107711762014175&w=2 mailing-listx_refsource_BUGTRAQ
- http://marc.info/?l=bugtraq&m=107712137732553&w=2 vendor-advisoryx_refsource_TRUSTIX
- http://marc.info/?l=bugtraq&m=107755871932680&w=2 vendor-advisoryx_refsource_TRUSTIX
- http://security.gentoo.org/glsa/glsa-200403-02.xml vendor-advisoryx_refsource_GENTOOPatchVendor Advisory
- http://www.ciac.org/ciac/bulletins/o-082.shtml third-party-advisorygovernment-resourcex_refsource_CIAC
- http://www.debian.org/security/2004/dsa-438 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-439 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.debian.org/security/2004/dsa-440 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-441 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-442 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-444 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-450 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-453 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-454 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-456 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-466 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-470 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-475 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2004/dsa-514 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/981222 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/3986 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2004-065.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2004-066.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2004-069.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2004-106.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/9686 vdb-entryx_refsource_BIDExploitPatchVendor Advisory
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404734 vendor-advisoryx_refsource_SLACKWARE
- https://access.redhat.com/security/cve/CVE-2004-0077 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617138 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15244 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2004-0077
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A825 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A837 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2004-0077
Change history (0)
No recorded changes yet.