CVE-2011-4127
published 2012-07-03CVE-2011-4127: The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write…
PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.57%
43.6th percentile
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libguestfs | < libguestfs 1:1.14.8-1 (bookworm) | libguestfs 1:1.14.8-1 (bookworm) |
| libguestfs | libguestfs | >= 0 < 1:1.14.8-1 | 1:1.14.8-1 |
| libguestfs | libguestfs | >= 0 < 1:1.14.8-1 | 1:1.14.8-1 |
| libguestfs | libguestfs | >= 0 < 1:1.14.8-1 | 1:1.14.8-1 |
| libguestfs | libguestfs | >= 0 < 1:1.14.8-1 | 1:1.14.8-1 |
| linux | linux_kernel | <= 3.2.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-03-27·CVSS 4.6
CVE-2011-4127 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in the Linux kernel's ext4 file system when mounting a
corrupt filesystem. A user-assisted remote attacker could exploit this flaw
to cause a denial of service. (CVE-2012-2100)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 4.6
CVE-2011-4127 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denial of service by starting a timer. (CVE-2011-4622)
A flaw was discovered in the XFS filesystem. If a local user mounts a
specially crafted XFS image it could potential execute arbitrary code on
the system. (CVE-2012-0038)
A flaw was found in the Linux kernel's ext4 file system when mounting a
corr
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 5.5
CVE-2011-4097 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the Linux kernel's calculation of OOM (Out of
memory) scores, that would result in the wrong process being killed. A user
could use this to kill the process with the highest OOM score, even if that
process belongs to another user or the system. (CVE-2011-4097)
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denia
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-03-06·CVSS 4.6
CVE-2011-4127 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Paolo Bonzini discovered a flaw in Linux's handling of the SG_IO ioctl
command. A local user, or user in a VM could exploit this flaw to bypass
restrictions and gain read/write access to all data on the affected block
device. (CVE-2011-4127)
A flaw was found in KVM's Programmable Interval Timer (PIT). When a virtual
interrupt control is not available a local user could use this to cause a
denial of service by starting a timer. (CVE-2011-4622)
A flaw was discovered in the XFS filesystem. If a local user mounts a
specially crafted XFS image it could potential execute arbitrary code on
the system. (CVE-2012-0038)
A flaw was found in the Linux kernel's ext4 file system when mounting a
corrupt fi
Red Hat
kernel: possible privilege escalation via SG_IO ioctl
vendor_redhat·2011-12-22·CVSS 4.6
CVE-2011-4127 [MEDIUM] CWE-284 kernel: possible privilege escalation via SG_IO ioctl
kernel: possible privilege escalation via SG_IO ioctl
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0107.html, https://rhn.redhat.com/errata/RHSA-2011-1849.html, and https://rhn.redhat.com/errata/RHSA-2012-0333.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/upda
Debian
CVE-2011-4127: libguestfs - The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, whic...
vendor_debian·2011·CVSS 4.6
CVE-2011-4127 [MEDIUM] CVE-2011-4127: libguestfs - The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, whic...
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Scope: local
bookworm: resolved (fixed in 1:1.14.8-1)
bullseye: resolved (fixed in 1:1.14.8-1)
forky: resolved (fixed in 1:1.14.8-1)
sid: resolved (fixed in 1:1.14.8-1)
trixie: resolved (fixed in 1:1.14.8-1)
GHSA
GHSA-hffv-wrg3-v4pp: The Linux kernel before 3
ghsa_unreviewed·2022-05-14
CVE-2011-4127 [MEDIUM] GHSA-hffv-wrg3-v4pp: The Linux kernel before 3
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
OSV
CVE-2011-4127: The Linux kernel before 3
osv·2012-07-03·CVSS 4.6
CVE-2011-4127 [MEDIUM] CVE-2011-4127: The Linux kernel before 3
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
No detection rules found.
No public exploits indexed.
Bugzilla
qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation)
bugzilla·2012-05-29·CVSS 4.6
CVE-2011-4127 [MEDIUM] qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation)
qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation)
Cloning against F16
+++ This bug was initially created as a clone of Bug #770135 +++
+++ This bug was initially created as a clone of Bug #756677 +++
qemu-kvm does have a "scsi" option (to be used like -device
virtio-blk-pci,drive=foo,scsi=off). However, it only masks the feature
bit, and does not reject the command if a malicious guest disregards
the feature bits and issues a request.
(CVE-2011-4127 mitigation)
--- Additional comment from [email protected] on 2011-11-25 12:56:27 EST ---
How to test:
1) install guest which storage is backed by partition or LV (for example: -drive file=/dev/VolGroup/bz756677,if=none,id=drive-virt0-0-1,format=raw,cache=none,aio=threads -device virtio-blk-pci,drive=
Bugzilla
qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation) [rhel-6.3]
bugzilla·2011-12-23·CVSS 4.6
CVE-2011-4127 [MEDIUM] qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation) [rhel-6.3]
qemu-kvm: virtio-blk: refuse SG_IO requests with scsi=off (CVE-2011-4127 mitigation) [rhel-6.3]
+++ This bug was initially created as a clone of Bug #756677 +++
qemu-kvm does have a "scsi" option (to be used like -device
virtio-blk-pci,drive=foo,scsi=off). However, it only masks the feature
bit, and does not reject the command if a malicious guest disregards
the feature bits and issues a request.
(CVE-2011-4127 mitigation)
--- Additional comment from [email protected] on 2011-11-25 12:56:27 EST ---
How to test:
1) install guest which storage is backed by partition or LV (for example: -drive file=/dev/VolGroup/bz756677,if=none,id=drive-virt0-0-1,format=raw,cache=none,aio=threads -device virtio-blk-pci,drive=drive-virt0-0-1,id=virt0-0-1)
2) patch and rebuild the guest kernel:
commen
Bugzilla
CVE-2011-4127 kernel: possible privilege escalation via SG_IO ioctl [fedora-all]
bugzilla·2011-12-22·CVSS 4.6
CVE-2011-4127 [MEDIUM] CVE-2011-4127 kernel: possible privilege escalation via SG_IO ioctl [fedora-all]
CVE-2011-4127 kernel: possible privilege escalation via SG_IO ioctl [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2011-4127 kernel: possible privilege escalation via SG_IO ioctl
bugzilla·2011-11-09·CVSS 4.6
CVE-2011-4127 [MEDIUM] CVE-2011-4127 kernel: possible privilege escalation via SG_IO ioctl
CVE-2011-4127 kernel: possible privilege escalation via SG_IO ioctl
Paolo Bonzini of Red Hat found out that the host Linux system allows
executing the SG_IO ioctl on a partition or even on an LVM volume, and
will pass the command to the underlying block device. This could be
further exploited in the context of virtualization, because virtio disks
support a limited form of SCSI passthrough via the SG_IO ioctl. If
virtio disk is hosted on a partition or LVM volume with format=raw,
tools such as sg_dd can be used to read and write other data on the same
disk --- even data that belongs to the host or to other guests.
References:
https://lkml.org/lkml/2004/8/12/218
https://lkml.org/lkml/2004/8/12/260
Discussion:
rhel-5 doesn't implement SG_IO passthrough in virtio-blk (unlike rhel-6) which
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0bfc96cb77224736dfa35c3c555d37b3646ef35ehttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ec8013beddd717d1740cfefb1a9b900deef85462http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://secunia.com/advisories/48898http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2http://www.openwall.com/lists/oss-security/2011/12/22/5https://bugzilla.redhat.com/show_bug.cgi?id=752375https://github.com/torvalds/linux/commit/0bfc96cb77224736dfa35c3c555d37b3646ef35ehttps://github.com/torvalds/linux/commit/ec8013beddd717d1740cfefb1a9b900deef85462http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0bfc96cb77224736dfa35c3c555d37b3646ef35ehttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ec8013beddd717d1740cfefb1a9b900deef85462http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://secunia.com/advisories/48898http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2http://www.openwall.com/lists/oss-security/2011/12/22/5https://bugzilla.redhat.com/show_bug.cgi?id=752375https://github.com/torvalds/linux/commit/0bfc96cb77224736dfa35c3c555d37b3646ef35ehttps://github.com/torvalds/linux/commit/ec8013beddd717d1740cfefb1a9b900deef85462
2012-07-03
Published