CVE-2018-10545: Canonical Ubuntu Linux

Medium severity, CVSS 4.7. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Netapp Storage Automation Store: affected versions not specified
  • PHP PHP: before 5.6.35 (fixed in 5.6.35); from 7.0.0, before 7.0.29 (fixed in 7.0.29); from 7.1.0, before 7.1.16 (fixed in 7.1.16); from 7.2.0, before 7.2.4 (fixed in 7.2.4)

Published 2018-04-29. Last modified 2026-06-17.