Back

CVE-2003-0985

The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.

Published: Jan 20, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (54)

Vendor Product Version
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.0
linux linux_kernel 2.4.1
linux linux_kernel 2.4.2
linux linux_kernel 2.4.3
linux linux_kernel 2.4.4
linux linux_kernel 2.4.5
linux linux_kernel 2.4.6
linux linux_kernel 2.4.7

…and 34 more

GitHub Security Advisory GHSA-p4qr-c64v-fjhc

The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 1.23%

Top 34% most likely to be exploited

Threat Score 29.2 / 100

Data Sources

NVD EPSS GitHub