VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2017-18200
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-18200
CVSS severity score: 4.9/10.0
Description:
The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Mar 17 2018Status: WontFix (was: Untriaged)
Upstream commit 638164a2718f337 ("f2fs: fix potential panic during fstrim"). chromeos-4.14 not affected per CVE. Fixes commit 969d1b180d987 ("f2fs: introduce discard_granularity sysfs entry") which is not in chromeos-4.4. On top of that, F2FS_FS is not enabled in ChromeOS images. WontFix.