Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2004-0077

29
FAUCET Score

CVE-2004-0077 describes a local privilege escalation vulnerability in the do_mremap function within the Linux kernel (versions 2.2 through 2.6.2). This flaw, affecting various Linux distributions, stems from improper handling of return values from do_munmap when the maximum number of VMA descriptors is exceeded. With a CVSS score of 7.2, it represents a high-severity vulnerability allowing an authenticated local attacker to gain root privileges with low attack complexity and no user interaction. While not on the KEV catalog, exploit code is publicly available on ExploitDB, indicating its exploitability. Despite this, there is minimal community discussion or media coverage surrounding this older vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
2.4.20-8CPE matchmatch criteria
cpe:2.3:a:redhat:bigmem_kernel:2.4.20-8:*:i686:*:*:*:*:*
2.4.20-8CPE matchmatch criteria
cpe:2.3:a:redhat:kernel:2.4.20-8:*:athlon_smp:*:*:*:*:*
2.4.20-8CPE matchmatch criteria
cpe:2.3:a:redhat:kernel:2.4.20-8:*:i386:*:*:*:*:*
2.4.20-8CPE matchmatch criteria
cpe:2.3:a:redhat:kernel:2.4.20-8:*:i686_smp:*:*:*:*:*
2.4.20-8CPE matchmatch criteria
cpe:2.3:a:redhat:kernel_doc:2.4.20-8:*:i386:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.43%
Probability of exploitation in next 30 days
EPSS Percentile
82.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-160 · Mar 1, 2004
This CVE's current EPSS score of 0.0243 is in the 94th percentile among its peer group of 3,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

debianpatch availablevia nvd_reference
View patch
gentoopatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: s390utils-2:1.2.4-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AS (Advanced Server) version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux ES version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux WS version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux Advanced Workstation 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: kernel-0:2.4.21-9.0.1.EL
View patch

Vendor Advisories (1)

redhatCVE-2004-0077Important

security flaw

Feb 18, 2004

References

archives.neohapsis.com / archives/vulnwatch/2004-q1/0040.html
distro.conectiva.com.br / atualizacoes
fedoranews.org / updates/FEDORA-2004-079.shtml
frontal2.mandriva.com / security/advisories
isec.pl / vulnerabilities/isec-0014-mremap-unmap.txt
marc.info
marc.info
marc.info
security.gentoo.org / glsa/glsa-200403-02.xml
PatchVendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/15244
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A825
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A837
ciac.org / ciac/bulletins/o-082.shtml
debian.org / security/2004/dsa-438
debian.org / security/2004/dsa-439
PatchVendor Advisory
debian.org / security/2004/dsa-440
debian.org / security/2004/dsa-441
debian.org / security/2004/dsa-442
debian.org / security/2004/dsa-444
debian.org / security/2004/dsa-450
debian.org / security/2004/dsa-453
debian.org / security/2004/dsa-454
debian.org / security/2004/dsa-456
debian.org / security/2004/dsa-466
debian.org / security/2004/dsa-470
debian.org / security/2004/dsa-475
debian.org / security/2004/dsa-514
kb.cert.org / vuls/id/981222
US Government Resource
novell.com / linux/security/advisories/2004_05_linux_kernel.html
osvdb.org / 3986
redhat.com / support/errata/RHSA-2004-065.html
redhat.com / support/errata/RHSA-2004-066.html
redhat.com / support/errata/RHSA-2004-069.html
redhat.com / support/errata/RHSA-2004-106.html
securityfocus.com / bid/9686
ExploitPatchVendor Advisory
slackware.com / security/viewer.php