Arbitrary Code Execution via Failed mmap Function Call in Linux Kernel

Arbitrary Code Execution via Failed mmap Function Call in Linux Kernel

CVE-2004-1071 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.