New issue
Advanced search Search tips

Issue 835552 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: Bug-Security



Sign in to add a comment

CVE-2018-8822 CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Apr 21 2018

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2018-8822
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-8822
  CVSS severity score: 7.2/10.0
  Description:

Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 

Comment 1 by groeck@chromium.org, Apr 23 2018

Cc: wonderfly@google.com zsm@chromium.org
Labels: Security_Severity-High Security_Impact-None Pri-3
Owner: groeck@chromium.org
Status: WontFix (was: Untriaged)
Upstream commit 4c41aa24baa4ed338 ("staging: ncpfs: memory corruption in ncp_read_kernel()"). Fixed in chromeos-4.4 with merge of v4.4.125. Fixed in chromeos-4.14 with merge of v4.14.31. IPX and with it NCPFS is not enabled in ChromeOS images, thus ChromeOS not affected. Assuming that Lakitu isn't affected either, marking as WontFix.


Sign in to add a comment