vulnerability

Oracle Linux: CVE-2018-1126: ELSA-2018-1777: procps security update (IMPORTANT) (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:L/Au:S/C:P/I:P/A:P)
Published
2018-05-17
Added
2018-05-24
Modified
2025-01-07

Description

procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
A flaw was found where procps-ng provides wrappers for standard C allocators that took `unsigned int` instead of `size_t` parameters. On platforms where these differ (such as x86_64), this could cause integer truncation, leading to undersized regions being returned to callers that could then be overflowed. The only known exploitable vector for this issue is CVE-2018-1124.

Solution(s)

oracle-linux-upgrade-procpsoracle-linux-upgrade-procps-develoracle-linux-upgrade-procps-ngoracle-linux-upgrade-procps-ng-develoracle-linux-upgrade-procps-ng-i18n
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.