A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the /proc/<pid>/cmdline (or /proc/<pid>/environ) files to block indefinitely (denial of service) or for some controlled time (as a synchronization primitive for other attacks).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2018-06-20 13:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-1120
Mitre link : CVE-2018-1120
CVE.ORG link : CVE-2018-1120
JSON object : View
Products Affected
debian
- debian_linux
canonical
- ubuntu_linux
redhat
- enterprise_linux_workstation
- enterprise_linux_server
- virtualization_host
- enterprise_linux_desktop
linux
- linux_kernel