New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 721731 link

Starred by 1 user

Issue metadata

Status: Archived
Owner:
Last visit > 30 days ago
Closed: May 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, May 12 2017

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2017-7895
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-7895
  CVSS severity score: 10/10.0
  Description:

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 
Components: OS>Kernel
Labels: Security_Severity-High Security_Impact-Stable Pri-1
Owner: groeck@chromium.org
Status: Assigned (was: Untriaged)
groeck@, can you please help to find owner and check if existing labels (severity, impact) look good.
Labels: M-58

Comment 3 by groeck@chromium.org, May 15 2017

Owner: andreyu@google.com
Also see b:38261521.

Comment 4 by andreyu@google.com, May 15 2017

Do we have any boards that use 3.x kernels and enable NFSD? The following CLs fix this in 4.4 and are being cherry-picked into release branches as per  http://crbug.com/721925 : 
https://chromium-review.googlesource.com/c/505167/
https://chromium-review.googlesource.com/c/505168/

Comment 5 by groeck@chromium.org, May 15 2017

#4: The only configuration I am aware of which enables NFSD is Lakitu, but that is on 4.4.

Comment 6 by dgreid@google.com, May 15 2017

We will also enable it on our VM guests, but they are all on 4.4 as well.

Comment 7 by andreyu@google.com, May 22 2017

Status: Fixed (was: Assigned)
Project Member

Comment 8 by sheriffbot@chromium.org, May 23 2017

Labels: Restrict-View-SecurityNotify
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 29 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 10 by dchan@chromium.org, Jan 22 2018

Status: Archived (was: Fixed)

Sign in to add a comment