CVE-2026-23059 PUBLISHED

Reported by redhat · Published February 28, 2013

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a
linuxlinux_kernel2.6.19, 2.6.19, 2.6.19
LinuxLinux0, 5.10.248, 5.15.198

Timeline

References

Open in Interactive Console →