Issue metadata
Sign in to add a comment
|
CVE-2017-18257 CrOS: Vulnerability reported in Linux kernel |
||||||||||||||||||||||||
Issue descriptionVOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. Advisory: CVE-2017-18257 Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-18257 CVSS severity score: 4.9/10.0 Description: The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl. This bug was filed by http://go/vomit Please contact us at vomit-team@google.com if you need any assistance.
,
May 11 2018
Upstream b86e33075ed1 ("f2fs: fix a dead loop in f2fs_fiemap()"). Per CVE, not an issue in chromeos-4.14. Not yet fixed in older kernels. Will request to be added to upstream stable releases and pick up from there once available.
,
May 11 2018
,
May 18 2018
Fixed in v4.4.132. Marking as duplicate of merge bug.
,
Aug 24
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by mnissler@chromium.org
, May 11 2018Labels: Security_Impact-None Security_Severity-Low