CVE-2018-1121 PUBLISHED

procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also.

EPSS 1.88% · 83.0th percentile

Risk Scores

EPSS Score
1.88%
83.0th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-oracle-6.86.8.0-1011.11~22.04.1, 6.8.0-1008.8~22.04.1, 6.8.0-1006.6~22.04.3
Ubuntu:22.04:LTSlinux-hwe-5.195.19.0-35.36~22.04.1, 5.19.0-38.39~22.04.1, 5.19.0-40.41~22.04.1
Ubuntu:22.04:LTSlinux-nvidia-tegra-igx5.15.0-1029.29, 5.15.0-1031.31, 5.15.0-1032.32
Ubuntu:Pro:18.04:LTSlinux-gcp-4.154.15.0-1093.106, 4.15.0-1092.105, 4.15.0-1090.103
Ubuntu:Pro:20.04:LTSlinux-aws5.4.0-1122.132, 5.4.0-1124.134, 5.4.0-1154.164
Ubuntu:22.04:LTSlinux-nvidia5.15.0-1007.7, 5.15.0-1041.41, 5.15.0-1040.40
Ubuntu:22.04:LTSlinux-nvidia-6.86.8.0-1047.50~22.04.1, 6.8.0-1046.49~22.04.1, 6.8.0-1045.48~22.04.1
Ubuntu:Pro:20.04:LTSlinux-azure-5.155.15.0-1103.112~20.04.1, 5.15.0-1040.47~20.04.1, 5.15.0-1041.48~20.04.1
Ubuntu:25.10linux0, 6.14.0-15.15, 6.15.0-3.3
Ubuntu:18.04:LTSlinux-oracle-5.35.3.0-1030.32~18.04.1, 5.3.0-1028.30~18.04.1, 5.3.0-1027.29~18.04.1
Ubuntu:24.04:LTSlinux-oracle6.8.0-1024.25, 6.8.0-1044.45, 6.8.0-1043.44
Ubuntu:22.04:LTSlinux-riscv-5.195.19.0-1021.23~22.04.1, 5.19.0-1020.22~22.04.1, 5.19.0-1019.21~22.04.1
Ubuntu:24.04:LTSlinux-oem-6.176.17.0-1012.12, 0, 6.17.0-1005.5
Ubuntu:18.04:LTSlinux-gcp-edge5.0.0-1013.13~18.04.1, 5.0.0-1011.11~18.04.1, 4.18.0-1015.16~18.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-fips4.15.0-1100.111, 4.15.0-1099.110, 4.15.0-1098.109
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1039.46~20.04.1.1, 5.15.0-1037.44~20.04.1.1, 5.15.0-1036.43~20.04.1.1
Ubuntu:Pro:Realtime:24.04:LTSlinux-realtime-6.140, 6.14.0-1003.3~24.04.3, 6.14.0-1010.10~24.04.1
Ubuntu:Pro:Realtime:24.04:LTSlinux-realtime6.8.1-1037.38, 6.8.1-1013.14, 6.8.1-1012.12
Ubuntu:22.04:LTSlinux-intel-iotg5.15.0-1040.46, 5.15.0-1060.66, 5.15.0-1061.67
Ubuntu:22.04:LTSlinux-azure-fde-6.26.2.0-1014.14~22.04.1.1, 6.2.0-1015.15~22.04.1.1, 6.2.0-1019.19~22.04.1.1

…and 218 more

Timeline

References

Open in Interactive Console →