Issue metadata
Sign in to add a comment
|
CVE-2018-18386 CrOS: Vulnerability reported in Linux kernel |
||||||||||||||||||||||
Issue descriptionVOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. Advisory: CVE-2018-18386 Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-18386 CVSS severity score: 2.1/10.0 Description: drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ. This bug was filed by http://go/vomit Please contact us at vomit-team@google.com if you need any assistance.
,
Dec 7
@1: As usual, please keep in mind that Chrome OS kernels are not only used by Chrome OS nowadays. As such, I tend to stick with our common evaluation and do not try to make calls like that.
Upstream commit 966031f340185 ("n_tty: fix EXTPROC vs ICANON interaction with TIOCINQ (aka FIONREAD)"). Fixed in chromeos-{4.4,4.14,4.19}. Low severity, thus marking as WontFix for older kernels.
,
Dec 7
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by kerrnel@chromium.org
, Dec 7