{"api_version":"1","generated_at":"2026-07-23T06:51:46+00:00","cve":"CVE-2004-0491","urls":{"html":"https://cve.report/CVE-2004-0491","api":"https://cve.report/api/cve/CVE-2004-0491.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0491","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0491"},"summary":{"title":"CVE-2004-0491","description":"The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=linux-kernel&m=108087017610947&w=2","name":"http://marc.info/?l=linux-kernel&m=108087017610947&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Re: disable-cap-mlock' - MARC","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19607","name":"http://secunia.com/advisories/19607","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SGI ProPack kernel Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/13769","name":"http://www.securityfocus.com/bid/13769","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Linux Kernel Local MEMLOCK RLIMIT Bypass Denial Of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U","name":"ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-472.html","name":"http://www.redhat.com/support/errata/RHSA-2005-472.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411","name":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"126411 – CVE-2004-0491 mlock accounting issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0491","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0491","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"491","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:17:15.250Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"oval:org.mitre.oval:def:10672","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672"},{"name":"oval:org.mitre.oval:def:1117","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117"},{"name":"19607","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19607"},{"name":"RHSA-2005:472","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2005-472.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411"},{"name":"[linux-kernel] 20040402 Re: disable-cap-mlock","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=linux-kernel&m=108087017610947&w=2"},{"name":"20060402-01-U","tags":["vendor-advisory","x_refsource_SGI","x_transferred"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U"},{"name":"13769","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13769"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-04-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"oval:org.mitre.oval:def:10672","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672"},{"name":"oval:org.mitre.oval:def:1117","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117"},{"name":"19607","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19607"},{"name":"RHSA-2005:472","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2005-472.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411"},{"name":"[linux-kernel] 20040402 Re: disable-cap-mlock","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=linux-kernel&m=108087017610947&w=2"},{"name":"20060402-01-U","tags":["vendor-advisory","x_refsource_SGI"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U"},{"name":"13769","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13769"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0491","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oval:org.mitre.oval:def:10672","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10672"},{"name":"oval:org.mitre.oval:def:1117","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1117"},{"name":"19607","refsource":"SECUNIA","url":"http://secunia.com/advisories/19607"},{"name":"RHSA-2005:472","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2005-472.html"},{"name":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126411"},{"name":"[linux-kernel] 20040402 Re: disable-cap-mlock","refsource":"MLIST","url":"http://marc.info/?l=linux-kernel&m=108087017610947&w=2"},{"name":"20060402-01-U","refsource":"SGI","url":"ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U"},{"name":"13769","refsource":"BID","url":"http://www.securityfocus.com/bid/13769"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0491","datePublished":"2005-02-06T05:00:00.000Z","dateReserved":"2004-05-27T00:00:00.000Z","dateUpdated":"2024-08-08T00:17:15.250Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*","matchCriteriaId":"40D8DAE0-8E75-435C-9BD6-FAEED2ACB47C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"491","Ordinal":"1","Title":"CVE-2004-0491","CVE":"CVE-2004-0491","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"491","Ordinal":"1","NoteData":"The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.","Type":"Description","Title":"CVE-2004-0491"},{"CveYear":"2004","CveId":"491","Ordinal":"2","NoteData":"2005-02-06","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"491","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}