New issue
Advanced search Search tips

Issue 743613 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CrOS: CVE-2017-10911: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Jul 15 2017

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2017-10911
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-10911
  CVSS severity score: 4.9/10.0
  Description:

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 

Comment 1 by raymes@chromium.org, Jul 15 2017

Labels: Security_Severity-Low Security_Impact-Stable
Owner: sonnyrao@chromium.org
Status: Assigned (was: Untriaged)
sonnyrao: please take a look at this one too. 

Comment 2 by groeck@chromium.org, Jul 16 2017

Summary: CrOS: CVE-2017-10911: Vulnerability reported in Linux kernel (was: CrOS: Vulnerability reported in Linux kernel)
upstream commit 089bc0143f489bd3a4578bdff5f4ca68fb26f341

Project Member

Comment 3 by sheriffbot@chromium.org, Jul 16 2017

Labels: Pri-2
Owner: groeck@chromium.org
Hi -- apologies I was unexpectedly out last week - Guenter could you take a look?

Comment 5 by groeck@chromium.org, Jul 26 2017

I can, but I'll be on PTO until next Wednesday. It waited so long, guess it can wait a bit longer.

Status: WontFix (was: Assigned)
Applying the upstream patch causes conflicts. We don't use Xen, and thus won't be able to test patch results. As such, risk of fixing the problem is higher than just leaving it alone.

Sign in to add a comment