Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1121
HistoryMay 18, 2018 - 5:19 a.m.

CVE-2018-1121

2018-05-1805:19:54
redhat.com
access.redhat.com
16

0.002 Low

EPSS

Percentile

55.0%

Since the kernel’s proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng’s utilities by exploiting a race condition in reading /proc/PID entries.