security flaw
Published Apr 30, 2004
2.1
LOWCVSS 2.0
EPSS 0.47%
Description
The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.
Affected products
No data.
- ≥ 2.4.0 · < 2.4.26
- ≥ 2.6.0 · < 2.6.6
No data.
Red Hat Enterprise Linux 3
kernel-0:2.4.21-15.0.2.EL
Fixed · RHSA-2004:255
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2004:327
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2004:327
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | kernel-0:2.4.21-15.0.2.EL | Fixed | RHSA-2004:255 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2004:327 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2004:327 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.47% (0.00468) | 38.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.47% (0.00468) | 36.70th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.11% (0.00107) | 26.40th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00047) | 19.20th | v3 (v2023.03.01) |
| May 1, 2024 | 0.05% (0.00047) | 15.93th | v3 (v2023.03.01) |
| Jan 27, 2024 | 0.05% (0.00047) | 13.91th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00065) | 26.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (38)
- ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc vendor-advisoryx_refsource_SGIBroken LinkPatchVendor Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc vendor-advisoryx_refsource_SGIBroken LinkPatchVendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846 vendor-advisoryx_refsource_CONECTIVABroken Link
- http://fedoranews.org/updates/FEDORA-2004-111.shtml vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://linux.bkbits.net:8080/linux-2.4/cset%40407bf20eDeeejm8t36_tpvSE-8EFHA x_refsource_MISCBroken Link
- http://linux.bkbits.net:8080/linux-2.6/cset%40407b1217x4jtqEkpFW2g_-RcF0726A x_refsource_MISCBroken Link
- http://marc.info/?l=linux-kernel&m=108139073506983&w=2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://secunia.com/advisories/11429 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/11464 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/11486 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/11541 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/11861 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/11891 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/11892 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/20162 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/20163 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/20202 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/20338 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200407-02.xml vendor-advisoryx_refsource_GENTOOBroken Link
- http://www.ciac.org/ciac/bulletins/o-164.shtml third-party-advisorygovernment-resourcex_refsource_CIACBroken Link
- http://www.debian.org/security/2006/dsa-1067 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.debian.org/security/2006/dsa-1069 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.debian.org/security/2006/dsa-1070 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.debian.org/security/2006/dsa-1082 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:037 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.novell.com/linux/security/advisories/2004_10_kernel.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.redhat.com/support/errata/RHSA-2004-255.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2004-260.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2004-327.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/10221 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.turbolinux.com/security/2004/TLSA-2004-14.txt vendor-advisoryx_refsource_TURBOBroken Link
- https://access.redhat.com/security/cve/CVE-2004-0427 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617207 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16002 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2004-0427
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10297 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2819 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2004-0427
Change history (0)
No recorded changes yet.