VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2017-12146
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-12146
CVSS severity score: 6.9/10.0
Description:
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Sep 19 2017Status: WontFix (was: Untriaged)
Upstream 6265539776a0810b ("driver core: platform: fix race condition with driver_override"). Already fixed in chromeos-4.12 and chromeos-4.4 through stable merges. Already fixed in chromeos-3.18 with b:65376271. Does not apply to older kernels.