VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2017-18232
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-18232
CVSS severity score: 2.1/10.0
Description:
The Serial Attached SCSI (SAS) implementation in the Linux kernel through 4.15.9 mishandles a mutex within libsas, which allows local users to cause a denial of service (deadlock) by triggering certain error-handling code.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by groeck@chromium.org
, Apr 11 2018Status: WontFix (was: Untriaged)
Upstream commit 0558f33c06bb91 ("scsi: libsas: direct call probe and destruct"). LIBSAS is not enabled in ChromeOS images. We'll pull the fix from stable releases if/when applied there.