CVE-2017-14180: Apport Project Apport
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
Affected products
- Apport Project Apport: from 2.13, up to and including 2.20.7
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.04 only; version 17.10 only; version 18.04 only
Published 2018-02-02. Last modified 2026-06-17.