VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2018-1066
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-1066
CVSS severity score: 7.1/10.0
Description:
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by zsm@chromium.org
, Mar 23 2018Labels: Security_Severity-Low Security_Impact-None Pri-3
Owner: zsm@chromium.org
Status: WontFix (was: Untriaged)
Fix is cabfb3680f("CIFS: Enable encryption during session setup phase") Fix is present on 4.14. The fix does not cleanly apply and CONFIG_CIFS does not seem to be set on any of the kernels, so marking as WontFix.