CVE-2012-2313
published 2012-06-13CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows…
PriorityP410low1.2CVSS 2.0
AVLACHAuNCNINAP
EPSS
0.56%
42.6th percentile
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.19-1 (bookworm) | linux 3.2.19-1 (bookworm) |
| linux | linux_kernel | <= 3.3.6 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| linux | linux_kernel | >= 0 < 3.2.19-1 | 3.2.19-1 |
| novell | suse_linux_enterprise_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_long_life | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:N/A:P
osv1.2LOW
vendor_ubuntu4.9MEDIUM
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
Steve Grubb reported a flaw with Linux fscaps (file system base
capabilities) when used to increase the permissions of a process. For
application on which fscaps are in use a local attacker can disable address
space randomization to make attacking the process with raised privileges
easier. (CVE-2012-2123)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-29·CVSS 1.2
CVE-2012-2313 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-06-15·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
han
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-06-13·CVSS 4.9
CVE-2012-2121 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsp
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-13·CVSS 4.9
CVE-2012-2121 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)
Timo Warns reported multiple flaws in the Linux kernel's hfsplus
file
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network driver's
handling of
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-06-12·CVSS 4.6
CVE-2011-4131 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Adamson discovered a flaw in the Linux kernel's NFSv4 implementation.
A remote NFS server (attacker) could exploit this flaw to cause a denial of
service. (CVE-2011-4131)
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Schacher Raindel discovered a flaw in the Linux kernel's memory handling
when hugetlb is enabled. An unprivileged local attacker could exploit this
flaw to cause a denial of service and potentially gain higher privileges.
(CVE-2012-2133)
Stephan Mueller reported a flaw in the Linux kernel's dl2k network d
Red Hat
kernel: unfiltered netdev rio_ioctl access by users
vendor_redhat·2012-04-26·CVSS 1.2
CVE-2012-2313 [LOW] kernel: unfiltered netdev rio_ioctl access by users
kernel: unfiltered netdev rio_ioctl access by users
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
Package: kernel (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2012-2313: linux - The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel ...
vendor_debian·2012·CVSS 1.2
CVE-2012-2313 [LOW] CVE-2012-2313: linux - The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel ...
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
Scope: local
bookworm: resolved (fixed in 3.2.19-1)
bullseye: resolved (fixed in 3.2.19-1)
forky: resolved (fixed in 3.2.19-1)
sid: resolved (fixed in 3.2.19-1)
trixie: resolved (fixed in 3.2.19-1)
GHSA
GHSA-gjcc-798m-m76x: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k
ghsa_unreviewed·2022-05-17
CVE-2012-2313 [LOW] GHSA-gjcc-798m-m76x: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
OSV
CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k
osv·2012-06-13·CVSS 1.2
CVE-2012-2313 [LOW] CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2313 kernel: unfiltered netdev rio_ioctl access by users [fedora-all]
bugzilla·2012-05-04·CVSS 1.2
CVE-2012-2313 [LOW] CVE-2012-2313 kernel: unfiltered netdev rio_ioctl access by users [fedora-all]
CVE-2012-2313 kernel: unfiltered netdev rio_ioctl access by users [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=secur
Bugzilla
CVE-2012-2313 kernel: unfiltered netdev rio_ioctl access by users
bugzilla·2012-05-04·CVSS 1.2
CVE-2012-2313 [LOW] CVE-2012-2313 kernel: unfiltered netdev rio_ioctl access by users
CVE-2012-2313 kernel: unfiltered netdev rio_ioctl access by users
The dl2k driver's rio_ioctl call has a few issues:
- No permissions checking
- Implements SIOCGMIIREG and SIOCGMIIREG using the SIOCDEVPRIVATE numbers
- Has a few ioctls that may have been used for debugging at one point but have no place in the kernel proper.
This patch removes all but the MII ioctls, renumbers them to use the standard ones, and adds the proper permission check for SIOCSMIIREG.
We can also get rid of the dl2k-specific struct mii_data in favor of the generic struct mii_ioctl_data.
Since we have the phyid on hand, we can add the SIOCGMIIPHY ioctl too.
Most of the MII code for the driver could probably be converted to use the generic MII library but I don't have a device to test the results.
Upstream com
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1bb57e940e1958e40d51f2078f50c3a96a9b2d75http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-1174.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1481.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1541.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1589.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.7http://www.openwall.com/lists/oss-security/2012/05/04/8http://www.securityfocus.com/bid/53965https://bugzilla.redhat.com/show_bug.cgi?id=818820https://github.com/torvalds/linux/commit/1bb57e940e1958e40d51f2078f50c3a96a9b2d75http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1bb57e940e1958e40d51f2078f50c3a96a9b2d75http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://marc.info/?l=bugtraq&m=139447903326211&w=2http://rhn.redhat.com/errata/RHSA-2012-1174.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1481.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1541.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1589.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.7http://www.openwall.com/lists/oss-security/2012/05/04/8http://www.securityfocus.com/bid/53965https://bugzilla.redhat.com/show_bug.cgi?id=818820https://github.com/torvalds/linux/commit/1bb57e940e1958e40d51f2078f50c3a96a9b2d75
2012-06-13
Published