CVE-2004-0497

Linux kernel <2.x - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0497. PoCs published by Marco Ivaldi.

AI-analyzed exploit summary This exploit leverages a Linux kernel vulnerability (CVE-2004-0497) where the `chown` system call lacks proper DAC controls, allowing local users to change the group ownership of files they do not own. It demonstrates privilege escalation by modifying group permissions on sensitive files like `/etc/shadow`.

Description

Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Marco Ivaldi · clocallinux
https://www.exploit-db.com/exploits/718

This exploit leverages a Linux kernel vulnerability (CVE-2004-0497) where the `chown` system call lacks proper DAC controls, allowing local users to change the group ownership of files they do not own. It demonstrates privilege escalation by modifying group permissions on sensitive files like `/etc/shadow`.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Linux kernel 2.2.x, 2.4.x < 2.4.27-rc3, 2.6.x < 2.6.7-rc3
No auth needed
Prerequisites: Local access to a vulnerable Linux system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-354.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16599
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9867
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-360.html
Patch, Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066
Patch, Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2004_20_kernel.html

Scores

EPSS 0.0080
EPSS Percentile 51.8%

Details

Status published
Products (18)
conectiva/linux 10
gentoo/linux
linux/linux_kernel 2.0
mandrakesoft/mandrake_linux 9.1
mandrakesoft/mandrake_linux 9.2
mandrakesoft/mandrake_linux 10.0
mandrakesoft/mandrake_linux_corporate_server 2.1
mandrakesoft/mandrake_multi_network_firewall 8.2
redhat/enterprise_linux 2.1 (3 CPE variants)
redhat/enterprise_linux 3.0 (3 CPE variants)
... and 8 more
Published Dec 06, 2004
Tracked Since Feb 18, 2026