CVE-2018-1121 describes a race condition vulnerability in procps-ng and procps up to version 3.3.15, allowing an unprivileged attacker to hide processes from system utilities. This is achieved by manipulating PID assignments during /proc directory scanning. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high complexity, but a high impact on integrity (process hiding). While it doesn't directly lead to system compromise, it can facilitate evasion of detection. Currently, there is no evidence of active exploitation (KEV and Hot List are inactive), and no Metasploit or Nuclei modules exist. However, an ExploitDB entry (EDB-44806) suggests proof-of-concept code is available, and there has been some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.15CPE matchmatch criteria | cpe:2.3:a:procps_project:procps:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.