CVE-2018-1124: Integer Overflow
Last updated 25 August 2025
Other sources
Multiple integer overflows leading to heap corruption in file2strvec() lead to privilege escalation for a local attacker who can create entries in procfs by starting processes, which will lead to crashes or arbitrary code execution in proc utilities run by other users (eg pgrep, pkill, pidof, w)
— Red Hat
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-1124?
CVE-2018-1124 is a vulnerability in procps-ng before version 3.3.15 that allows a privilege escalation for a local attacker.
How severe is CVE-2018-1124?
CVE-2018-1124 has a severity rating of 7.8 (high).
How does CVE-2018-1124 occur?
CVE-2018-1124 is caused by multiple integer overflows leading to a heap corruption in the file2strvec function.
Which software versions are affected by CVE-2018-1124?
Procps-ng versions before 3.3.15 and certain versions of Debian, Ubuntu, Red Hat Enterprise Linux, openSUSE Leap, and Schneider-electric Struxureware Data Center Expert are affected.
How can I fix CVE-2018-1124?
To fix CVE-2018-1124, upgrade to version 3.3.15 of procps-ng or apply the recommended patches for the affected software.