VulnerabilityModified
CVE-2012-2313
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
LOW 1.2EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
- CVSS 2.0
- 1.2 LOWAV:L/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- linux/linux kernel · novell/suse linux enterprise server · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux long life · redhat/enterprise linux server aus · redhat/enterprise linux server eus
- Source
- secalert@redhat.com
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1bb57e940e1958e40d51f2078f50c3a96a9b2d75
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1174.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1481.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1541.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1589.htmlThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.7Release Notes
- http://www.openwall.com/lists/oss-security/2012/05/04/8Mailing List
- http://www.securityfocus.com/bid/53965Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=818820Issue Tracking
- https://github.com/torvalds/linux/commit/1bb57e940e1958e40d51f2078f50c3a96a9b2d75Exploit, Patch
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1bb57e940e1958e40d51f2078f50c3a96a9b2d75
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=139447903326211&w=2Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1174.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1481.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1541.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1589.htmlThird Party Advisory
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.7Release Notes
- http://www.openwall.com/lists/oss-security/2012/05/04/8Mailing List
- http://www.securityfocus.com/bid/53965Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=818820Issue Tracking
- https://github.com/torvalds/linux/commit/1bb57e940e1958e40d51f2078f50c3a96a9b2d75Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.