VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2017-16995
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-16995
CVSS severity score: 7.2/10.0
Description:
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Jan 10 2018Labels: M-65 Security_Severity-High Security_Impact-None Pri-2
Owner: groeck@chromium.org
Status: ExternalDependency (was: Untriaged)
Upstream commit 95a762e2c8c9427 ("bpf: fix incorrect sign extension in check_alu_op()"). Only relevant if BPF_SYSCALL is enabled, which is not the case in Chrome OS. Plan is to wait for the patch to be available from upstream stable, then merge into chromeos-4.4 and chromeos-4.14.