New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 888318 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Oct 15
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CVE-2018-10880 CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Sep 23

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2018-10880
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-10880
  CVSS severity score: 7.1/10.0
  Description:

Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and a denial of service.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 
Cc: groeck@chromium.org wonderfly@google.com
Labels: Security_Severity-High Security_Impact-Stable Pri-1
Owner: zsm@chromium.org
Status: Assigned (was: Untriaged)
Upstream commit is 8a9ef17c0dc93("ext4: never move the system.data xattr out of the inode body").

This commit is present in v4.14. Older kernels(including v4.4) do not seem to have this commit.
Cc: sawlani@google.com
#1: Upstream commit is 8cdb5240ec5("ext4: never move the system.data xattr out of the inode body").
Project Member

Comment 4 by sheriffbot@chromium.org, Sep 25

Labels: M-69 Target-69
Matching bug in buganizer: https://buganizer.corp.google.com/issues/116406043


patch sent to upstream stable, attached.
0001-ext4-never-move-the-system.data-xattr-out-of-the-ino.patch
1.7 KB Download
patch is now in stable queue.
Status: Fixed (was: Assigned)
Patch is now in 4.4.y and v4.4.
Project Member

Comment 12 by sheriffbot@chromium.org, Oct 16

Labels: Restrict-View-SecurityNotify
Project Member

Comment 13 by sheriffbot@chromium.org, Today (17 hours ago)

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment