** Description changed:

- It was found that the default SCSI command filter does not accommodate
- commands that overlap across device classes. A privileged guest user
- could potentially use this flaw to write arbitrary data to a LUN that is
- passed-through as read-only.
+ block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly
+ consider the SCSI device class during authorization of SCSI commands,
+ which allows local users to bypass intended access restrictions via an
+ SG_IO ioctl call that leverages overlapping opcodes.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1131331

Title:
  CVE-2012-4542

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1131331/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to