CVE-2018-1123: Buffer Overflow
Published May 23, 2018
·Updated
Last updated 25 August 2025
Other sources
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).
— Launchpad
Affected Software
10 affected componentsFixes available
Procps-ng Project Procps-ng<3.3.15
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/procps
2:3.3.17-52:4.0.2-32:4.0.4-9
Remediation
Patch Available
Event History
May 23, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Dec 18, 2025
Data Sourced
via Ubuntu·08:50 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:50 PM
DescriptionAffected Software
Feb 21, 2026
Data Sourced
via Launchpad·06:41 PM
Description
Frequently Asked Questions
1
What is CVE-2018-1123?
CVE-2018-1123 is a vulnerability in procps-ng before version 3.3.15 that allows a denial of service in ps via mmap buffer overflow.
2
Which software versions are affected by CVE-2018-1123?
The affected software versions include procps-ng before version 3.3.15, 3.3.17-5, 4.0.2-3, and 4.0.4-2.
3
How severe is CVE-2018-1123?
CVE-2018-1123 has a severity rating of 7.5 (high).
4
What is the impact of CVE-2018-1123?
The impact of CVE-2018-1123 is a temporary denial of service (crash).
5
Is there a fix available for CVE-2018-1123?
Yes, the fix for CVE-2018-1123 is available in procps-ng version 3.3.15 and later.