Back

MEDIUM

kernel: proc: /proc/<pid>/mem mem_write insufficient permission checking

Published Jan 27, 2012

Description

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

Affected products

Remediation

Red Hat statement

This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as it did not backport the upstream commit 198214a7ee. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0052.html and https://rhn.redhat.com/errata/RHSA-2012-0061.html. For more information, please read https://access.redhat.com/kb/docs/DOC-69129.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 27, 2012
Updated Aug 6, 2024
Reserved Dec 7, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 18, 2012