PublicDateAtUSN: 2018-05-17 17:00:00 UTC Candidate: CVE-2018-1126 CRD: 2018-05-17 17:00:00 UTC PublicDate: 2018-05-23 13:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1126 https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt https://ubuntu.com/security/notices/USN-3658-1 https://ubuntu.com/security/notices/USN-3658-2 Description: procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. Ubuntu-Description: Notes: mdeslaur> [PATCH 035/117] proc/alloc.*: Use size_t, not unsigned int. Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_procps: upstream: https://gitlab.com/procps-ng/procps/commit/f1077b7a558a5545837aae068422e58f1f9b1d33 upstream_procps: released (3.3.15) precise/esm_procps: released (1:3.2.8-11ubuntu6.5) trusty_procps: released (1:3.3.9-1ubuntu2.3) trusty/esm_procps: released (1:3.3.9-1ubuntu2.3) xenial_procps: released (2:3.3.10-4ubuntu2.4) esm-infra/xenial_procps: released (2:3.3.10-4ubuntu2.4) artful_procps: released (2:3.3.12-1ubuntu2.1) bionic_procps: released (2:3.3.12-3ubuntu1.1) devel_procps: released (2:3.3.15-2ubuntu1)