VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2018-6412
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-6412
CVSS severity score: 5/10.0
Description:
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Feb 23 2018Owner: groeck@chromium.org
Status: WontFix (was: Untriaged)