VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2017-14954
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-14954
CVSS severity score: 2.1/10.0
Description:
The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Oct 7 2017Labels: Security_Impact-Stable Security_Severity-Low M-62 Pri-1
Owner: groeck@chromium.org
Status: Assigned (was: Untriaged)
Upstream 6c85501f2fabc ("fix infoleak in waitid(2)"). Affects all kernel versions.