Linux Kernel SG_IO ioctl Bug Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1026453 |
|
SecurityTracker URL: http://securitytracker.com/id/1026453
|
|
CVE Reference:
CVE-2011-4127
(Links to External Site)
|
Date: Dec 22 2011
|
Impact:
Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information, Root access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in the Linux Kernel. A local user can obtain elevated privileges on the target system.
On a virtualized system, a local privileged user on the guest operating system can execute the SG_IO ioctl on a partition or LVM volume to read or write data on the underlying disk. The local user can access host operating system data or data of other guests on the system.
Paolo Bonzini of Red Hat reported this vulnerability.
|
Impact:
A local privileged user on the guest operating system can obtain elevated privileges on the target system.
|
Solution:
A proposed source code fix is available.
|
Vendor URL: www.kernel.org/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|