New issue
Advanced search Search tips

Issue 916959 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jan 3
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

CVE-2018-19407 CrOS: Vulnerability reported in Linux kernel

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Dec 20

Issue description

VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel. 

Advisory: CVE-2018-19407
  Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2018-19407
  CVSS severity score: 4.9/10.0
  Description:

The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized.



This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.

 
Owner: zsm@chromium.org
Status: Assigned (was: Untriaged)
Cc: groeck@chromium.org wonderfly@google.com
Labels: Security_Severity-Medium Security_Impact-Stable Pri-2
The upstream fix is
     e97f852fd456 ("KVM: X86: Fix scan ioapic use-before-initialization")

This patch is present in chromeos-4.19, v4.14.
v4.4 and older do not have this patch. 4.4.y does not have this patch.

Will send a backport to stable if the PoC reproduces the crash.
Cc: rkolchmeyer@google.com
Project Member

Comment 4 by sheriffbot@chromium.org, Dec 21

Labels: Target-72 M-72
Project Member

Comment 5 by sheriffbot@chromium.org, Dec 21

Labels: -Pri-2 Pri-1
Labels: -Security_Impact-Stable Security_Impact-None
Status: WontFix (was: Assigned)
I tried running this PoC on a chromebook(astronaut) with a 4.4 kernel and was unable to reproduce this crash. Marking this bug as WontFix.
(For future reference the PoC can be found at https://lkml.org/lkml/2018/11/20/580)

Sign in to add a comment