procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 4.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade procps | May 24, 2018 | May 22, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade procps-ng | Jul 23, 2018 | May 23, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade procps-ng | Aug 10, 2018 | May 23, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2018 |
| Suse | — | Upgrade procps-develUpgrade libprocps7Upgrade libprocps3Upgrade procps | Jun 29, 2018 | May 22, 2018 |
| Ubuntu | — | Upgrade libprocps4Upgrade libprocps6Upgrade procpsUpgrade libprocps3 | Jun 1, 2018 | May 22, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub