Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported.
NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.
Package Name: sys-kernel/chromeos-kernel-3_18
Package Version: [cpe:/o:linux:linux_kernel:3.18]
Advisory: CVE-2017-5897
Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2017-5897
CVSS severity score: 7.5/10.0
Confidence: high
Description:
The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
Comment 1 by nparker@chromium.org
, Sep 11 2017Status: Duplicate (was: Untriaged)