New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 643630 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in sys-kernel/chromeos-kernel-3_8

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Sep 2 2016

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: sys-kernel/chromeos-kernel-3_8
Package Version: [cpe:/o:linux:linux_kernel:3.8.11]

Advisory: CVE-2016-5342
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2016-5342
  CVSS severity score: 10/10.0
  Confidence: high
  Description:

Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service or possibly have unspecified other impact by writing to /dev/wcnss_wlan with an unexpected amount of data.
Advisory: CVE-2016-5344
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2016-5344
  CVSS severity score: 10/10.0
  Confidence: high
  Description:

Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified other impact via a large size value, related to mdss_compat_utils.c, mdss_fb.c, and mdss_rotator.c.


 

Comment 1 by vakh@chromium.org, Sep 2 2016

Components: OS>Kernel
Labels: Security_Severity-High Security_Impact-Head
Status: Available (was: Untriaged)

Comment 2 by vakh@chromium.org, Sep 2 2016

Owner: snanda@chromium.org
Cc: groeck@chromium.org cernekee@chromium.org dtor@chromium.org snanda@chromium.org
Status: WontFix (was: Available)
CVE-2016-5342 applies to drivers/net/wireless/wcnss/wcnss_wlan.c.  We don't include that driver in Chrome OS.

CVE-2016-5344 applies to drivers/video/msm/mdss.  We don't include that driver in Chrome OS.

Adding a few more folks just in case I missed something here.

Closing as WontFix since these CVEs are not applicable to Chrome OS.
Project Member

Comment 4 by sheriffbot@chromium.org, Dec 10 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment