New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 728559 link

Starred by 1 user

Issue metadata

Status: Archived
Owner:
Last visit > 30 days ago
Closed: Jun 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CrOS: CVE-2017-9077: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Jun 1 2017

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2017-9077
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-9077
  CVSS severity score: 7.2/10.0
  Description:

The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 
Components: OS>Kernel
Labels: Security_Severity-High Security_Impact-Stable
Owner: groeck@chromium.org
Bulk edit for recent vomit kernel issues.

groeck, are you the right owner for these? Feel free to pass it back to me for retriage if not.
Status: Assigned (was: Untriaged)
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 6 2017

Labels: M-59
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 6 2017

Labels: Pri-1
Summary: CrOS: CVE-2017-9077: Vulnerability reported in Linux kernel (was: CrOS: Vulnerability reported in Linux kernel)
Owner: andreyu@google.com
Status: Fixed (was: Assigned)
Duplicate of b:62265010, which has already been applied.

Status: Assigned (was: Fixed)
Andrey, please check if any cherry-picks are required.

Comment 8 by andreyu@google.com, Jun 7 2017

Labels: Merge-Request-60 Merge-Request-59
Project Member

Comment 9 by sheriffbot@chromium.org, Jun 7 2017

Labels: -Merge-Request-59 Merge-Review-59 Hotlist-Merge-Review
This bug requires manual review: Request affecting a post-stable build
Please contact the milestone owner if you have questions.
Owners: amineer@(Android), cmasso@(iOS), gkihumba@(ChromeOS), Abdul Syed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Jun 8 2017

Status: Fixed (was: Assigned)
Please mark security bugs as fixed as soon as the fix lands, and before requesting merges. This update is based on the merge- labels applied to this issue. Please reopen if this update was incorrect.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Jun 8 2017

Labels: -Merge-Request-60 Hotlist-Merge-Approved Merge-Approved-60
Your change meets the bar and is auto-approved for M60. Please go ahead and merge the CL to branch 3112 manually. Please contact milestone owner if you have questions.
Owners: amineer@(Android), cmasso@(iOS), josafat@(ChromeOS), bustamante@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 12 by sheriffbot@chromium.org, Jun 9 2017

Labels: Restrict-View-SecurityNotify
Labels: Merge-Approved-59
Project Member

Comment 14 by sheriffbot@chromium.org, Jun 13 2017

Cc: gkihumba@google.com
This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible!

If all merges have been completed, please remove any remaining Merge-Approved labels from this issue.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Merge-Review-59
Cc: -gkihumba@google.com

Comment 17 by andreyu@google.com, Jun 13 2017

Labels: -Merge-Approved-59 -Merge-Approved-60
Labels: -Hotlist-Merge-Review
Project Member

Comment 19 by sheriffbot@chromium.org, Sep 15 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 20 by dchan@chromium.org, Jan 22 2018

Status: Archived (was: Fixed)

Sign in to add a comment