CVE-2018-1125: Buffer Overflow
Published May 23, 2018
·Updated
Last updated 25 August 2025
Other sources
procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.
— Launchpad
Affected Software
11 affected componentsFixes available
Procps-ng Project Procps-ng<3.3.15
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Leap=15.1
debian/procps
2:3.3.17-52:4.0.2-32:4.0.4-9
Remediation
Event History
May 23, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:47 PM
Description
Dec 17, 2025
Data Sourced
via Ubuntu·08:49 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:50 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1125.
2
What software versions are affected by this vulnerability?
procps-ng versions before 3.3.15 are affected by this vulnerability.
3
What is the severity rating of this vulnerability?
This vulnerability has a severity rating of 7.5 (high).
4
How does this vulnerability manifest?
This vulnerability manifests as a stack buffer overflow in the pgrep utility.
5
Is there a fix available for this vulnerability?
Yes, the vulnerability can be fixed by updating procps-ng to version 3.3.15 or later.