CVE-2023-4016

NameCVE-2023-4016
DescriptionUnder some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1042887

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
procps (PTS)buster2:3.3.15-2vulnerable
bullseye2:3.3.17-5vulnerable
bookworm2:4.0.2-3vulnerable
sid, trixie2:4.0.4-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
procpssource(unstable)2:4.0.4-11042887

Notes

[bookworm] - procps <no-dsa> (Minor issue)
[bullseye] - procps <no-dsa> (Minor issue)
[buster] - procps <postponed> (Minor issue, DoS, rare conditions)
https://gitlab.com/procps-ng/procps/-/issues/297
https://gitlab.com/procps-ng/procps/-/commit/2c933ecba3bb1d3041a5a7a53a7b4078a6003413

Search for package or bug name: Reporting problems