Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-0291

18
FAUCET Score

CVE-2010-0291 is a local privilege escalation and denial-of-service vulnerability affecting the Linux kernel before version 2.6.32.4, specifically impacting Debian and other Linux distributions. The vulnerability, dubbed the "do_mremap() mess," allows local users to gain elevated privileges or trigger a system panic by manipulating the mmap or mremap functions. With a CVSS score of 4.6, it has a low attack complexity and requires local access, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this decade-old vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.32.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
5.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.6MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 66th percentile among its peer group of 3,052 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: MRG for RHEL-5Fixed in: kernel-rt-0:2.6.24.7-149.el5rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-194.8.1.el5
View patch

Vendor Advisories (2)

microsoft2010-Feb/CVE-2010-0291Moderate

The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."

Feb 2, 2010
redhatCVE-2010-0291Important

kernel: untangle the do_mremap()

Dec 7, 2009

References

git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
git.kernel.org
groups.google.co.jp / group/fa.linux.kernel/browse_thread/thread/8bf22336b1082090
Third Party Advisory
groups.google.com / group/linux.kernel/msg/895f20870532241e
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/38492
Third Party Advisory
secunia.com / advisories/39033
Third Party Advisory
secunia.com / advisories/43315
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11824
Third Party Advisory
debian.org / security/2010/dsa-1996
Third Party Advisory
debian.org / security/2010/dsa-2005
Third Party Advisory
kernel.org / pub/linux/kernel/v2.6/ChangeLog-2.6.32.4
PatchVendor Advisory
redhat.com / support/errata/RHSA-2010-0161.html
Third Party Advisory
securityfocus.com / archive/1/516397/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/37906
Third Party AdvisoryVDB Entry
vmware.com / security/advisories/VMSA-2011-0003.html
Third Party Advisory