CVE-2004-1983 describes a denial-of-service vulnerability in the PaX patches for Linux kernel 2.6, specifically within the arch_get_unmapped_area function when Address Space Layout Randomization (ASLR) is enabled. This flaw could allow local users to trigger an infinite loop, impacting systems running Gentoo Linux and other distributions utilizing the PaX patches. The vulnerability has a low severity CVSS score (AV:L/AC:L/Au:N/C:N/I:N/A:P), indicating local access and low attack complexity are required to achieve a partial availability impact. While there is an ExploitDB entry (EDB-24078) detailing a denial-of-service exploit, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.5CPE matchmatch criteria | cpe:2.3:a:the_pax_team:pax_linux:2.6.5:*:*:*:*:*:*:* | ||
1.4CPE matchmatch criteria | cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.