|
|
Log in / Subscribe / Register

kernel: restriction bypass

Package(s):kernel CVE #(s):CVE-2011-4127
Created:December 23, 2011 Updated:March 6, 2012
Description: From the Red Hat advisory:

* Using the SG_IO IOCTL to issue SCSI requests to partitions or LVM volumes resulted in the requests being passed to the underlying block device. If a privileged user only had access to a single partition or LVM volume, they could use this flaw to bypass those restrictions and gain read and write access (and be able to issue other SCSI commands) to the entire block device.

In KVM (Kernel-based Virtual Machine) environments using raw format virtio disks backed by a partition or LVM volume, a privileged guest user could bypass intended restrictions and issue read and write requests (and other SCSI commands) on the host, and possibly access the data of other guests that reside on the same underlying block device. Partition-based and LVM-based storage pools are not used by default. Refer to Red Hat Bugzilla bug 752375 for further details and a mitigation script for users who cannot apply this update immediately. (CVE-2011-4127, Important)

Alerts:
SUSE SUSE-SU-2015:0812-1 kernel 2015-04-30
Oracle ELSA-2013-1645 kernel 2013-11-26
openSUSE openSUSE-SU-2013:0927-1 kernel 2013-06-10
Oracle ELSA-2012-0862 kernel 2012-07-02
Oracle ELSA-2012-2022 kernel 2012-07-02
Oracle ELSA-2012-2022 kernel 2012-07-02
SUSE SUSE-SU-2012:0554-2 kernel 2012-04-26
SUSE SUSE-SU-2012:0554-1 Linux kernel 2012-04-23
Ubuntu USN-1405-1 linux 2012-03-27
Oracle ELSA-2012-0150 kernel 2012-03-07
Ubuntu USN-1389-1 linux 2012-03-06
Red Hat RHSA-2012:0358-01 kernel 2012-03-06
Ubuntu USN-1388-1 linux-ec2 2012-03-06
Ubuntu USN-1384-1 linux-lts-backport-oneiric 2012-03-06
Red Hat RHSA-2012:0333-01 kernel-rt 2012-02-23
Oracle ELSA-2012-0107 kernel 2012-02-10
Scientific Linux SL-kern-20120213 kernel 2012-02-13
CentOS CESA-2012:0107 kernel 2012-02-09
Red Hat RHSA-2012:0107-01 kernel 2012-02-09
SUSE SUSE-SU-2012:0153-2 Linux kernel 2012-02-06
SUSE SUSE-SU-2012:0153-1 kernel 2012-02-06
Scientific Linux SL-qemu-20120125 qemu-kvm 2012-01-25
Fedora FEDORA-2012-0861 kernel 2012-01-24
Oracle ELSA-2012-0050 qemu-kvm 2012-01-23
Fedora FEDORA-2012-0876 kernel 2012-01-24
Debian DSA-2389-1 linux-2.6 2012-01-15
Oracle ELSA-2012-0007 kernel 2012-01-12
Fedora FEDORA-2011-17388 libguestfs 2011-12-23
Fedora FEDORA-2011-17372 libguestfs 2011-12-23
Oracle ELSA-2011-1849 kernel 2011-12-27
Oracle ELSA-2011-2038 kernel 2011-12-27
Scientific Linux SL-kern-20111222 kernel 2011-12-22
Oracle ELSA-2011-2038 kernel 2011-12-27
CentOS CESA-2011:1849 kernel 2011-12-23
Red Hat RHSA-2011:1849-01 kernel 2011-12-22

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds