PT-2012-2268 · Linux+2 · Linux Kernel+2

Jüri Aedla

·

Published

2012-01-19

·

Updated

2024-06-15

·

CVE-2012-0056

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.2.2
Description The issue concerns the mem write function in the Linux kernel. When Address Space Layout Randomization (ASLR) is disabled, this function does not properly check permissions when writing to the /proc/(pid)/mem file. This allows local users to gain privileges by modifying process memory. This has been demonstrated by the Mempodipper exploit.
Recommendations For Linux kernel versions prior to 3.2.2, update to version 3.2.2 or later to resolve the issue. As a temporary workaround, consider enabling ASLR to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0052
CVE-2012-0056
OPENSUSE-SU-2024:10128-1
RHSA-2012:0052
RHSA-2012:0061
RHSA-2012_0052
USN-1336-1
USN-1342-1
USN-1364-1

Affected Products

Centos
Linux Kernel
Red Hat