CVE-2018-1120: Canonical Ubuntu Linux
Medium severity, CVSS 5.3. EPSS: 7.2% chance of exploitation in the next 30 days.
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the /proc/<pid>/cmdline (or /proc/<pid>/environ) files to block indefinitely (denial of service) or for some controlled time (as a synchronization primitive for other attacks).
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: before 4.17 (fixed in 4.17)
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat Virtualization Host: version 4.0 only
Published 2018-06-20. Last modified 2026-06-17.