Issue metadata
Sign in to add a comment
|
Security: CVE-2018-5383
Reported by
nathanb@lenovo-chrome.com,
Jun 4 2018
|
||||||||||||||||||||||
Issue descriptionThis is a high-priority request to understand Google's response to CVE-2018-5383, which is at the time of this writing not publicly disclosed. If Google have a statement describing the timeline of how Chrome OS will address this issue or at least can verify that you are working on it, that would be very helpful. Thanks!
,
Jun 4 2018
You might be able to find it under PSIRT-TA-201805-002 if you can't find it by CVE.
,
Jun 4 2018
Over to Chrome OS security folk.
,
Jun 4 2018
Per https://bugs.chromium.org/p/chromium/issues/detail?id=807486#c45: "For the record, this vulnerability was fixed for QCA6174 at crosreview.com/979373 which landed on 05/01/2018." But CCing folks who might know more.
,
Jun 4 2018
Greg has it right, as far as I know.
,
Jun 4 2018
nathanb: does that address your question?
,
Jun 4 2018
I can't view the linked bug, but if the linked fix addresses the issue then that is sufficient for me. I will record that it's been taken care of. Thanks!
,
Jun 5 2018
What release will this land in?
,
Jun 5 2018
May 1 is M-67.
,
Jun 5 2018
Sorry, *M-68* branched on May 11th. So this fix will go out in *M-68*.
,
Jun 5 2018
Understood, thank you.
,
Jun 5 2018
Bear in mind that the kernel functionality using this pairing mechanism was disabled in time for M67. The fix that landed for M68 was for Qualcomm-specific firmware.
,
Jun 11 2018
Marking as fixed since the information was provided.
,
Jun 11 2018
Thank you for the information! I would have moved this bug to a terminal state myself but I don't have the access for that :)
,
Jun 11 2018
,
Jun 11 2018
,
Jun 12 2018
,
Jul 27
,
Sep 18
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by mea...@chromium.org
, Jun 4 2018Status: Assigned (was: Unconfirmed)