Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1120

32
FAUCET Score

CVE-2018-1120 is a denial-of-service vulnerability affecting the Linux kernel before version 4.17, specifically impacting utilities like ps and w from psutils or procps, as well as other programs reading /proc/<pid>/cmdline or /proc/<pid>/environ files. An attacker can exploit this by mapping a FUSE-backed file into a process's memory containing command-line arguments or environment strings, causing these utilities to block indefinitely. With a CVSS score of 5.3 (MEDIUM), this vulnerability has a network attack vector and high attack complexity, leading to a denial of service. There is no evidence of active exploitation, though an exploit (EDB-44806) exists for procps-ng, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

2.8LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.3
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
7.29%
Probability of exploitation in next 30 days
EPSS Percentile
93.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-44806 · May 30, 2018
This CVE's current EPSS score of 0.0729 is in the 97th percentile among its peer group of 1,425 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-957.rt56.910.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-alt-0:4.14.0-115.el7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-957.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: kernel-0:3.10.0-693.76.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: kernel-0:3.10.0-693.76.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: kernel-0:3.10.0-693.76.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-693.76.1.rt56.676.el6rt
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2018-1120Moderate

kernel: fuse-backed file mmap-ed onto process cmdline arguments causes denial of service

May 17, 2018

References

access.redhat.com / errata/RHSA-2018:2948
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3083
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3096
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
seclists.org / oss-sec/2018/q2/122
ExploitMailing ListThird Party Advisory
git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2018/07/msg00020.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201805-14
Third Party Advisory
usn.ubuntu.com / 3752-1
Third Party Advisory
usn.ubuntu.com / 3752-2
Third Party Advisory
usn.ubuntu.com / 3752-3
Third Party Advisory
usn.ubuntu.com / 3910-1
usn.ubuntu.com / 3910-2
exploit-db.com / exploits/44806
ExploitThird Party AdvisoryVDB Entry
securityfocus.com / bid/104229
Third Party AdvisoryVDB Entry