CVE-2012-0056: Linux Kernel

Medium severity, CVSS 6.9. EPSS: 10.8% chance of exploitation in the next 30 days.

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

Affected products

  • Linux Linux Kernel: from 2.6.39, before 3.0.18 (fixed in 3.0.18); from 3.1, before 3.2.2 (fixed in 3.2.2)

Published 2012-01-27. Last modified 2026-06-16.