CVE-2004-0491
published 2004-12-31CVE-2004-0491: The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.36%
28.3th percentile
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-06-21·CVSS 2.1
CVE-2004-0491 [LOW] security flaw
security flaw
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
GHSA
GHSA-f79w-jc47-24f4: The linux-2
ghsa_unreviewed·2022-05-03
CVE-2004-0491 [LOW] GHSA-f79w-jc47-24f4: The linux-2
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-0491 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2004-0491 [LOW] CVE-2004-0491 security flaw
CVE-2004-0491 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
Bugzilla
Multiple Kernel vulnerabilities
bugzilla·2005-05-11
[MEDIUM] Multiple Kernel vulnerabilities
Multiple Kernel vulnerabilities
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Mozilla rulez!)
Description of problem:
Paul Starzetz of iSEC has found yet another bug in binfmt_elf.c. It can be abused to crash the kernel, perhaps even to break into the kernel land. See the advisory for details.
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Steps to Reproduce:
Additional info:
I've got a quick and dirty patch. I'll submit it ASAP.
Discussion:
Grr...Bugzilla assigned the bug to [email protected] rather than to
[email protected]
---
Created attachment 114264
The patch for CAN-2005-1263
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
This patch can be applied to FL kernel 2.4.20-43:
402e548b02382c015d6f5e5704370a1ba546598b
li
Bugzilla
CVE-2004-0491 mlock accounting issue
bugzilla·2004-06-21·CVSS 2.1
CVE-2004-0491 [LOW] CVE-2004-0491 mlock accounting issue
CVE-2004-0491 mlock accounting issue
The linux-2.4.21-mlock.patch included in RHEL3 has a hole. It is
intended to allow normal uses to mlock within it's rlimit's however
the accounting can be broken in the case of IPC: one process/user can
mlock, another process can unlock. The later process gets it's pages
mlocked decremented even though the former process got the increment.
This could lead to unprivileged users getting rights to mlock memory.
This issue was reported by Arjan around Jun07 and fixed in FC2 (1.427
on Jun11).
See also:
http://marc.theaimsgroup.com/?l=linux-kernel&m=108087017610947&w=2
Discussion:
Non-kABI-breaking patch posted for review on 27-Apr-2005,
removing this bug from precluded-kABI-breakage blocker list.
---
A fix for this problem has just been committed to t
ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://marc.info/?l=linux-kernel&m=108087017610947&w=2http://secunia.com/advisories/19607http://www.redhat.com/support/errata/RHSA-2005-472.htmlhttp://www.securityfocus.com/bid/13769https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117ftp://patches.sgi.com/support/free/security/advisories/20060402-01-Uhttp://marc.info/?l=linux-kernel&m=108087017610947&w=2http://secunia.com/advisories/19607http://www.redhat.com/support/errata/RHSA-2005-472.htmlhttp://www.securityfocus.com/bid/13769https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117
2004-12-31
Published