Back

HIGH

procps: Integer overflows leading to heap overflow in file2strvec

Published May 23, 2018

Description

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 23, 2018
Updated Dec 18, 2025
Reserved Dec 4, 2017
CISA Vulnrichment
Updated Dec 17, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 17, 2018