Unrestricted Access to Ethernet Adapter via SIOCSMIIREG IOCTL Command

Unrestricted Access to Ethernet Adapter via SIOCSMIIREG IOCTL Command

CVE-2012-2313 · LOW Severity

AV:L/AC:H/AU:N/C:N/I:N/A:P

The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.