PT-2012-1244 · Linux+3 · Linux Kernel+3

Paolo Bonzini

+1

·

Published

2012-08-21

·

Updated

2026-03-13

·

CVE-2012-4542

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.9
Description The issue is related to the scsi ioctl function in the Linux kernel, which does not properly consider the SCSI device class during authorization of SCSI commands. This allows local users to bypass intended access restrictions via an SG IO ioctl call that leverages overlapping opcodes. The vulnerability can be exploited to elevate privileges.
Recommendations For Linux kernel versions prior to 3.9, update to a version 3.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the SG IO ioctl call to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-00352
CESA-2013_0496
CVE-2012-4542
ECHO-D769-34A1-5760
RHSA-2013:0496
RHSA-2013:0579
RHSA-2013:0622
RHSA-2013:0882
RHSA-2013:0928
RHSA-2013_0496

Affected Products

Centos
Debian
Linux Kernel
Red Hat