CVE Vulnerabilities

CVE-2011-4080

Published: May 24, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:L/AC:H/Au:N/C:C/I:N/A:N
RedHat/V2
1.5 LOW
AV:L/AC:M/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*2.6.39 (excluding)
Red Hat Enterprise Linux 6RedHatkernel-0:2.6.32-220.13.1.el6*
LinuxUbuntuupstream*
Linux-armadaxpUbuntuupstream*
Linux-ec2Ubuntumaverick*
Linux-ec2Ubuntuupstream*
Linux-fsl-imx51Ubuntuupstream*
Linux-lts-backport-maverickUbuntuupstream*
Linux-lts-backport-nattyUbuntuupstream*
Linux-lts-backport-oneiricUbuntuupstream*
Linux-mvl-doveUbuntulucid*
Linux-mvl-doveUbuntuupstream*
Linux-ti-omap4Ubuntuupstream*

References