CVE-2018-1120: Canonical Ubuntu Linux

Medium severity, CVSS 5.3. EPSS: 7.2% chance of exploitation in the next 30 days.

A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the /proc/<pid>/cmdline (or /proc/<pid>/environ) files to block indefinitely (denial of service) or for some controlled time (as a synchronization primitive for other attacks).

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • Linux Linux Kernel: before 4.17 (fixed in 4.17)
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-06-20. Last modified 2026-06-17.