CVE-2026-2492 PUBLISHED

Reported by redhat · Published February 28, 2013

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

Affected Products

VendorProductVersions
n/an/an/a
linuxlinux_kernel4.8, 4.8, 4.8
LinuxLinux4.8, 0, 5.10.251
n/an/an/a

Timeline

References

…and 9 more

Open in Interactive Console →