CVE-2012-0056 is a local privilege escalation vulnerability affecting the Linux kernel before version 3.2.2. It arises from improper permission checks in the mem_write function when writing to /proc/<pid>/mem, specifically when ASLR is disabled. This vulnerability has a CVSS score of 6.9, indicating high severity with local access and medium attack complexity, leading to complete confidentiality, integrity, and availability compromise. Exploit code, known as "Mempodipper," is publicly available on ExploitDB, and the vulnerability has garnered significant community discussion and media coverage, although it is not currently on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.39, < 3.0.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.1, < 3.2.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.