The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_enterprise_server | Suse | 10-sp4 (including) | 10-sp4 (including) |