6.9

CVE-2013-6383

The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which allows local users to bypass intended access restrictions via a crafted ioctl call.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 2.6.12 < 3.2.53
LinuxLinux Kernel Version >= 3.3 < 3.4.69
LinuxLinux Kernel Version >= 3.5 < 3.10.19
LinuxLinux Kernel Version >= 3.11 < 3.11.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.048
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C