VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2018-10840
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-10840
CVSS severity score: 7.2/10.0
Description:
Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by zsm@chromium.org
, Sep 24Labels: Security_Severity-High Security_Impact-None Pri-3
Owner: zsm@chromium.org
Status: WontFix (was: Untriaged)
Upstream commit is 8a2b307c21 ("ext4: correctly handle a zero-length xattr with a non-zero e_value_offs"). This commit is present in v4.14, older kernels do not have this commit. Fixes tag suggests that this bug was introduced after 4.4.y.