Headline
Ubuntu Security Notice USN-6477-1
Ubuntu Security Notice 6477-1 - It was discovered that the procps-ng ps tool incorrectly handled memory. An attacker could possibly use this issue to cause procps-ng to crash, resulting in a denial of service.
==========================================================================
Ubuntu Security Notice USN-6477-1
November 14, 2023
procps vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
procps-ng could be made to crash if it received specially crafted input.
Software Description:
- procps: /proc file system utilities
Details:
It was discovered that the procps-ng ps tool incorrectly handled memory.
An attacker could possibly use this issue to cause procps-ng to crash,
resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
procps 2:4.0.3-1ubuntu1.23.10.1
Ubuntu 23.04:
procps 2:4.0.3-1ubuntu1.23.04.1
Ubuntu 22.04 LTS:
procps 2:3.3.17-6ubuntu2.1
Ubuntu 20.04 LTS:
procps 2:3.3.16-1ubuntu2.4
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
procps 2:3.3.12-3ubuntu1.2+esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
procps 2:3.3.10-4ubuntu2.5+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6477-1
CVE-2023-4016
Package Information:
https://launchpad.net/ubuntu/+source/procps/2:4.0.3-1ubuntu1.23.10.1
https://launchpad.net/ubuntu/+source/procps/2:4.0.3-1ubuntu1.23.04.1
https://launchpad.net/ubuntu/+source/procps/2:3.3.17-6ubuntu2.1
https://launchpad.net/ubuntu/+source/procps/2:3.3.16-1ubuntu2.4
Related news
Dell vApp Manger, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote attacker could potentially exploit this vulnerability to read arbitrary files from the target system.
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process. In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed during this time window. This issue impacts HyperCloud versions from 2.0.0 to before 2.0.3.
Red Hat Security Advisory 2023-7187-01 - An update for procps-ng is now available for Red Hat Enterprise Linux 8. Issues addressed include a buffer overflow vulnerability.
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.