VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2018-10878
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-10878
CVSS severity score: 6.1/10.0
Description:
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by zsm@chromium.org
, Sep 24Labels: Security_Severity-Medium Security_Impact-Stable Pri-2
Owner: zsm@chromium.org
Status: Assigned (was: Untriaged)
Upstream commits are :- 819b23f1c5 ("ext4: always check block group bounds in ext4_init_block_bitmap()") 77260807 ("ext4: make sure bitmaps and the inode table don't overlap with bg descriptors") These commits are present in v4.14, v4.4; they are not present in older kernels.