The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < 245d48c1ba3e7a1779c2f4cbc6f581ddc8a78e22 |