CVE-2017-14179: Apport Project Apport

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.

Affected products

  • Apport Project Apport: before 2.13 (fixed in 2.13)
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only; version 17.10 only; version 18.04 only

Published 2018-02-02. Last modified 2026-06-17.