DEBIAN-CVE-2011-4127

Advisory lineage Upstream: 1 Downstream: 2
Upstream
Published: 03 Jul 2012, 16:40
Last modified:28 Apr 2026, 20:07

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jul 2012, 16:40
Published
Vulnerability first disclosed
28 Apr 2026, 20:07
Last Modified
Vulnerability information updated

Description

The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.

Affected Systems

  • debianlibguestfs

    < 1:1.14.8-1 | < 1:1.14.8-1 | < 1:1.14.8-1 | < 1:1.14.8-1

References (1)