CVE-2012-4542 PUBLISHED

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

EPSS 0.08% · 22.7th percentile

Risk Scores

EPSS Score
0.08%
22.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlinux4.4.0-43.63, 4.4.0-278.312, 4.4.0-277.311
Ubuntu:22.04:LTSlinux-oracle5.15.0-1022.28, 5.15.0-1019.24, 5.15.0-1018.23
Ubuntu:24.04:LTSlinux-ibm0, 6.5.0-1009.9, 6.8.0-1001.1
Ubuntu:Pro:20.04:LTSlinux-oracle5.4.0-1052.56, 5.4.0-1054.58, 5.4.0-1055.59
Ubuntu:Pro:18.04:LTSlinux-kvm4.15.0-1079.81, 0, 4.15.0-1002.2
Ubuntu:Pro:14.04:LTSlinux3.13.0-151.201, 3.13.0-147.196, 3.13.0-145.194
Ubuntu:22.04:LTSlinux-starfive-6.50, 6.5.0-1007.8~22.04.1, 6.5.0-1008.9~22.04.1
Ubuntu:24.04:LTSlinux-hwe-6.116.11.0-19.19~24.04.1, 6.11.0-21.21~24.04.1, 6.11.0-24.24~24.04.1
Ubuntu:Pro:20.04:LTSlinux-azure5.4.0-1137.144, 5.4.0-1138.145, 5.4.0-1139.146
Ubuntu:24.04:LTSlinux-azure-fde-6.146.14.0-1013.13~24.04.1, 6.14.0-1014.14~24.04.1, 6.14.0-1015.15~24.04.1
Ubuntu:18.04:LTSlinux-gke-5.45.4.0-1063.66~18.04.1, 5.4.0-1080.86~18.04.1, 5.4.0-1078.84~18.04.1
Ubuntu:20.04:LTSlinux-oracle-5.85.8.0-1034.35~20.04.2, 5.8.0-1037.38~20.04.1, 5.8.0-1038.39~20.04.1
Ubuntu:22.04:LTSlinux-azure-fde-6.86.8.0-1042.49~22.04.1, 0, 6.8.0-1041.48~22.04.1
Ubuntu:24.04:LTSlinux-lowlatency-hwe-6.116.11.0-1014.15~24.04.1, 6.11.0-1013.14~24.04.1, 6.11.0-1011.12~24.04.1
Ubuntu:Pro:18.04:LTSlinux-raspi-5.45.4.0-1119.131~18.04.1, 5.4.0-1065.75~18.04.1, 5.4.0-1062.70~18.04.1
Ubuntu:24.04:LTSlinux-hwe-6.146.14.0-32.32~24.04.1, 6.14.0-33.33~24.04.1, 6.14.0-27.27~24.04.1
Ubuntu:20.04:LTSlinux-hwe-5.135.13.0-25.26~20.04.1, 5.13.0-23.23~20.04.2, 5.13.0-22.22~20.04.1
Ubuntu:Pro:16.04:LTSlinux-azure4.15.0-1192.207~16.04.1, 0, 4.11.0-1009.9
Ubuntu:22.04:LTSlinux-nvidia5.15.0-1092.93, 5.15.0-1091.92, 5.15.0-1090.91
Ubuntu:18.04:LTSlinux-oem4.15.0-1038.43, 4.15.0-1035.40, 4.15.0-1034.39

…and 218 more

Timeline

References

Open in Interactive Console →