procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Base Score: 3.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade procps | May 24, 2018 | May 22, 2018 |
| Gentoo Linux | — | Upgrade sys-process/procps. | May 31, 2018 | May 23, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade procps-ng | Jul 23, 2018 | May 23, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade procps-ng | Aug 10, 2018 | May 23, 2018 |
| Oracle_linux | — | Upgrade git-daemonUpgrade emacs-gitUpgrade git-emailUpgrade perl-GitUpgrade perl-Git-SVNUpgrade git-p4Upgrade git-svnUpgrade git-guiUpgrade git-hgUpgrade git-cvsUpgrade emacs-git-elUpgrade gitkUpgrade git-allUpgrade git-bzrUpgrade gitwebUpgrade git | Jun 21, 2018 | May 22, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2018 |
| Suse | — | Upgrade procpsUpgrade libprocps7Upgrade libprocps3Upgrade procps-devel | Jun 29, 2018 | May 22, 2018 |
| Ubuntu | — | Upgrade procpsUpgrade libprocps4Upgrade libprocps6Upgrade libprocps3 | Jun 1, 2018 | May 22, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub