Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FYI: CVEs #513

Closed
loveshack opened this issue Sep 23, 2021 · 6 comments
Closed

FYI: CVEs #513

loveshack opened this issue Sep 23, 2021 · 6 comments
Assignees

Comments

@loveshack
Copy link

In case you don't know, CVEs have been raised against libxsmm_gemm_generator again, at least CVE-2021-39535 ("NULL pointer dereference exists in JIT code", "Denial of Service") and CVE-2021-39536 ("JIT code has a heap-based buffer overflow") from the notification spam I've had from Fedora.
Unfortunately if you dismiss such things you get called highly irresponsible.

@hfp hfp self-assigned this Sep 23, 2021
@hfp
Copy link
Collaborator

hfp commented Sep 23, 2021

@loveshack Thank you, Dave!

I will take a look asap.

@loveshack
Copy link
Author

loveshack commented Sep 23, 2021 via email

@hfp
Copy link
Collaborator

hfp commented Sep 28, 2021

The CVEs are both fixed since August 2020 (~time when issues were reported). However, we made no release since then which is including the fixes. I will check if 1.16.3 is feasible with just these fixes.

@loveshack
Copy link
Author

loveshack commented Sep 28, 2021 via email

@hfp
Copy link
Collaborator

hfp commented Sep 29, 2021

Issue #287 was a different flow like filing CVEs without ever talking to us just for the sake of claiming something for publication (somewhat blaming this project). I consider the #398 and #402 absolutely valid claims including the reporting flow. Though, libxsmm_gemm_generator is a legacy tool which is kept for compatibility with some applications (they know how to not pass invalid input). However, ASAN (or similar tools) used to check upstreamed bits make a valid case worth to get our attention.

@hfp
Copy link
Collaborator

hfp commented Oct 14, 2021

Let me close your report since v1.16.3 was published to address the two CVEs. Thank you again for raising attention for the upstream work and process!

@hfp hfp closed this as completed Oct 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants