Release date:
Updated on: 2011-12-23
Affected Systems:
Linux kernel 2.6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51176
Cve id: CVE-2011-4127
Linux is the kernel of a free computer.
The Host Linux system allows you to execute SG_IO ioct1 on a partition or LVM volume and PASS commands to the lower-layer block device. Local attackers with restricted access permissions on certain partitions or LVM volumes can exploit this vulnerability to bypass the target restriction and use specially crafted SCSI commands to obtain access to the entire block device. Client operating system users can exploit this vulnerability to obtain data from the Host system or other Guest systems in some KVM environments.
<* Source: Paolo Bonzini
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 752375
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/