New issue
Advanced search Search tips

Issue 879544 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Oct 12
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

CVE-2018-13053 CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Aug 31

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2018-13053
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-13053
  CVSS severity score: 4.6/10.0
  Description:

The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 
Cc: groeck@chromium.org wonderfly@google.com
Labels: Security_Severity-Low Security_Impact-Stable Pri-3
Owner: zsm@chromium.org
Status: Assigned (was: Untriaged)
Upstream commit is 5f936e19cc ("alarmtimer: Prevent overflow for relative nanosleep"). This commit is present in v4.14(but not in stable upstream). Older kernels do not have this commit.
Unclear if this bug alone can be used for privesc, but will request upstream stable merge of this patch.
#1: "commit is present in v4.14" - are you sure ? I didn't see it there. What am I missing ?


Project Member

Comment 5 by sheriffbot@chromium.org, Sep 1

Labels: -Pri-3 Pri-2
Cc: adityakali@google.com
pre-cqs succeed for the CLs, some paladins are having errors.

cheza-paladin succeeds here : https://cros-goldeneye.corp.google.com/chromeos/healthmonitoring/buildDetails?buildbucketId=8936301616402889712

kevin-paladin succeeds here : https://cros-goldeneye.corp.google.com/chromeos/healthmonitoring/buildDetails?buildbucketId=8936301656347205376

I've requested this patch to be pulled into 4.14.y and 4.4.y
Status: ExternalDependency (was: Assigned)
Status: Fixed (was: ExternalDependency)
Patch is now in v4.14 and v4.4 via stable merge.
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 13

Labels: Restrict-View-SecurityNotify
Project Member

Comment 11 by sheriffbot@chromium.org, Jan 19 (3 days ago)

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment