Issue metadata
Sign in to add a comment
|
CrOS: Vulnerability reported in Linux kernel |
||||||||||||||||||||||
Issue descriptionVOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. Advisory: CVE-2017-1000363 Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-1000363 CVSS severity score: 7.2/10.0 Description: Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a vulnerability the adversary has partial control over the command line) can overflow the parport_nr array in the following code, by appending many (>LP_NO) 'lp=none' arguments to the command line. This bug was filed by http://go/vomit Please contact us at vomit-team@google.com if you need any assistance.
,
Jul 30 2017
,
Jul 30 2017
Seems like a WontFix but I'll let groeck@ decide.
,
Aug 2 2017
Already fixed in chromeos-4.4 via stable release merge. Won't fix in older kernerls per #1. Won't apply to stable releases per #1.
,
Aug 2 2017
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by grundler@google.com
, Jul 28 2017