CVE-2012-2313
Not scored
CVE-2012-2313
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
Exploit probability
0.6%
Published
June 13, 2012
Required by
Not available
Last source change
April 10, 2026
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2012-2313
View original source
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
05 / REFERENCES
Further evidence
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1bb57e940e1958e40d51f2078f50c3a96a9b2d75
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://rhn.redhat.com/errata/RHSA-2012-1174.html
- http://rhn.redhat.com/errata/RHSA-2012-1481.html
- http://rhn.redhat.com/errata/RHSA-2012-1541.html
- http://rhn.redhat.com/errata/RHSA-2012-1589.html
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.3.7
- http://www.openwall.com/lists/oss-security/2012/05/04/8
- http://www.securityfocus.com/bid/53965
- https://bugzilla.redhat.com/show_bug.cgi?id=818820
- https://github.com/torvalds/linux/commit/1bb57e940e1958e40d51f2078f50c3a96a9b2d75