← All CVEs

CVE-2012-0056

medium · 6.9

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

6.9
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2012-01-27
Published

AV:L/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 2.6.39, < 3.0.18
linuxlinux_kernel>= 3.1, < 3.2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0056