Procps Project maintains the procps process-monitoring utility, a foundational component across Linux distributions that parses and displays system process information. The vulnerability profile centers on memory-safety and concurrency issues, with recurrent weaknesses including race conditions, heap-based buffer overflows, and out-of-bounds writes that reflect the low-level parsing and multi-threaded access patterns inherent to process enumeration. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Procps Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1121MEDIUM procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupyin | Jun 13, 2018 | 5.9 | 30 | NO | YES |
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the | Aug 2, 2023 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Procps Project.
Media articles that mention a CVE ID that affects a product developed by Procps Project — matched by CVE ID, not by vendor name.