New issue
Advanced search Search tips

Issue 774775 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CVE-2017-14991 CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Oct 14 2017

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2017-14991
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-14991
  CVSS severity score: 2.1/10.0
  Description:

The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_TABLE ioctl call for /dev/sg0.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 

Comment 1 by groeck@google.com, Oct 14 2017

Upstream 3e0097499839 ("scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE").

Comment 2 by groeck@chromium.org, Oct 14 2017

Cc: wonderfly@google.com
Labels: Security_Severity-Low Security_Impact-Stable M-62 Pri-1
Owner: groeck@chromium.org
Status: Assigned (was: Untriaged)
Note: Will fix in chromeos-4.4 with the merge of 4.4.92 since there are several other fixes in the affected file. Will need to determine if all those patches are needed in backports and throttle branches.

Project Member

Comment 3 by sheriffbot@chromium.org, Oct 15 2017

Labels: -Pri-1 Pri-2

Comment 4 by groeck@chromium.org, Oct 16 2017

Status: Started (was: Assigned)
Cc: adityakali@google.com cloud-image-security@google.com
Owner: wonderfly@chromium.org
Bug is fixed in chromeos-4.4. 
wonderfly@: Can you determine if this patch is needed in M-62 and/or M-63 for Lakitu ?

Owner: groeck@chromium.org
No, this doesn't affect lakitu at all.
Status: WontFix (was: Started)
Marking as WontFix: Not needed for Lakitu, limited impact and too complex for older kernels, not worth the risk for stable releases.


Sign in to add a comment