Back

MEDIUM

kernel: fuse-backed file mmap-ed onto process cmdline arguments causes denial of service

Published Jun 20, 2018

Description

A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the /proc/<pid>/cmdline (or /proc/<pid>/environ) files to block indefinitely (denial of service) or for some controlled time (as a synchronization primitive for other attacks).

Affected products

Remediation

No remediation recorded yet.

References (20)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jun 20, 2018
Updated Aug 5, 2024
Reserved Dec 4, 2017

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 17, 2018
Bugzilla 1575472

ENISA EUVD

Assigner redhat
Published Jun 20, 2018
Updated Aug 5, 2024

GitHub

No data