Back

CVE-2004-0077

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

Published: Mar 3, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (112)

Vendor Product Version
redhat bigmem_kernel 2.4.20-8
redhat kernel 2.4.20-8
redhat kernel 2.4.20-8
redhat kernel 2.4.20-8
redhat kernel_doc 2.4.20-8
redhat kernel_source 2.4.20-8
linux linux_kernel 2.2.0
linux linux_kernel 2.2.1
linux linux_kernel 2.2.2
linux linux_kernel 2.2.3
linux linux_kernel 2.2.4
linux linux_kernel 2.2.5
linux linux_kernel 2.2.6
linux linux_kernel 2.2.7
linux linux_kernel 2.2.8
linux linux_kernel 2.2.9
linux linux_kernel 2.2.10
linux linux_kernel 2.2.11
linux linux_kernel 2.2.12
linux linux_kernel 2.2.13

…and 92 more

GitHub Security Advisory GHSA-pm7j-3492-hq9m

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 2.43%

Top 17% most likely to be exploited

Threat Score 29.5 / 100

Data Sources

NVD EPSS GitHub