Linux Kernel Unauthorized SCSI Command Vulnerability
BID:14040
Info
Linux Kernel Unauthorized SCSI Command Vulnerability
| Bugtraq ID: | 14040 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 23 2005 12:00AM |
| Updated: | Jun 23 2005 12:00AM |
| Credit: | The discoverer of this issue is currently unknown. |
| Vulnerable: |
Linux kernel 2.6.11 .8 Linux kernel 2.6.11 .7 Linux kernel 2.6.11 .6 Linux kernel 2.6.11 .5 Linux kernel 2.6.11 .11 Linux kernel 2.6.11 -rc4 Linux kernel 2.6.11 -rc3 Linux kernel 2.6.11 -rc2 Linux kernel 2.6.11 Linux kernel 2.6.10 rc2 Linux kernel 2.6.10 Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.8 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 .10 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 |
| Not Vulnerable: |
Linux kernel 2.6.12 -rc1 |
Discussion
Linux Kernel Unauthorized SCSI Command Vulnerability
Linux kernel is reported susceptible to an unauthorized SCSI command vulnerability.
Commands sent to a SCSI device may render the device's state inconsistent or change the drive parameters so that other users find the drive to be unusable.
It is possible that this issue is related to BID 11784 (SuSE Linux Kernel Unauthorized SCSI Command Vulnerability). This is not confirmed at the moment, however, this BID will be updated or the two BIDs will be combined into one when further analysis is completed.
Linux kernel is reported susceptible to an unauthorized SCSI command vulnerability.
Commands sent to a SCSI device may render the device's state inconsistent or change the drive parameters so that other users find the drive to be unusable.
It is possible that this issue is related to BID 11784 (SuSE Linux Kernel Unauthorized SCSI Command Vulnerability). This is not confirmed at the moment, however, this BID will be updated or the two BIDs will be combined into one when further analysis is completed.
Exploit / POC
Linux Kernel Unauthorized SCSI Command Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Kernel Unauthorized SCSI Command Vulnerability
Solution:
Kernel version 2.6.12-rc1 is not affected by this issue.
Solution:
Kernel version 2.6.12-rc1 is not affected by this issue.
References
Linux Kernel Unauthorized SCSI Command Vulnerability
References:
References:
- kernel.org Homepage. (Linux Kernel)
- Summary of changes from v2.6.11 to v2.6.12-rc1 (kernel.org)