New issue
Advanced search Search tips

Issue 813321 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: Bug-Security



Sign in to add a comment

CVE-2017-16911 CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Feb 17 2018

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2017-16911
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-16911
  CVSS severity score: 1.9/10.0
  Description:

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 

Comment 1 by groeck@chromium.org, Feb 17 2018

Cc: wonderfly@google.com zsm@chromium.org
Labels: Security_Severity-Low M-66 Security_Impact-Stable Pri-3
Owner: groeck@chromium.org
Status: WontFix (was: Untriaged)
Fixed in chromeos-4.14 with merge of v4.14.8. Fixed in chromeos-4.4 with merge of v4.4.114. Don't bother for older kernels since they leak kernel addresses to user space all over the place. Impact low, thus not needed in stable releases.

Sign in to add a comment