CVE-2012-2313: Low severity linux kernel vulnerability

Published May 4, 2012
·
Updated

Last updated 24 July 2024

Other sources

The dl2k driver's rioioctl call has a few issues: - No permissions checking - Implements SIOCGMIIREG and SIOCGMIIREG using the SIOCDEVPRIVATE numbers - Has a few ioctls that may have been used for debugging at one point but have no place in the kernel proper. This patch removes all but the MII ioctls, renumbers them to use the standard ones, and adds the proper permission check for SIOCSMIIREG. We can also get rid of the dl2k-specific struct miidata in favor of the generic struct miiioctldata. Since we have the phyid on hand, we can add the SIOCGMIIPHY ioctl too.

Most of the MII code for the driver could probably be converted to use the generic MII library but I don't have a device to test the results.

Upstream commit: http://git.kernel.org/linus/1bb57e940e1958e40d51f2078f50c3a96a9b2d75

Acknowledgements:

Red Hat would like to thank Stephan Mueller for reporting this issue.

Red Hat

The rioioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

Launchpad

Affected Software

23 affected componentsFixes available
Linux Linux kernel<=3.3.6
Linux Linux kernel=3.3
Linux Linux kernel=3.3-rc1
Linux Linux kernel=3.3-rc2
Linux Linux kernel=3.3-rc3
Linux Linux kernel=3.3-rc4
Linux Linux kernel=3.3-rc5
Linux Linux kernel=3.3-rc6
Linux Linux kernel=3.3-rc7
Linux Linux kernel=3.3.1
Linux Linux kernel=3.3.2
Linux Linux kernel=3.3.3
Linux Linux kernel=3.3.4
Linux Linux kernel=3.3.5
Novell Suse Linux Enterprise Server=10.0-sp4
redhat Enterprise Linux=5
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Eus=5.6.z
redhat Enterprise Linux Long Life=5.6
redhat Enterprise Linux Server Aus=6.2
redhat Enterprise Linux Server Eus=6.1.z
redhat Enterprise Linux Server Eus=6.2.z
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

May 4, 2012
Data Sourced
via Red Hat·05:38 AM
DescriptionSeverityAffected Software
Jun 13, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:58 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·12:49 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·01:17 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2012-2313?

CVE-2012-2313 is classified as a high-severity vulnerability due to its potential to allow unauthorized access and execution of inappropriate ioctls in the Linux kernel.

2

How do I fix CVE-2012-2313?

To fix CVE-2012-2313, it is recommended to upgrade to a patched version of the Linux kernel beyond 3.3.6.

3

Which versions of Linux kernel are affected by CVE-2012-2313?

CVE-2012-2313 affects Linux kernel versions 3.3 and earlier, including all release candidates and specific versions up to 3.3.6.

4

What are the implications of CVE-2012-2313 for my system?

The implications of CVE-2012-2313 include possible exploitation by attackers to gain elevated privileges and execute unauthorized commands within the kernel.

5

Is there a workaround for CVE-2012-2313 if I cannot upgrade?

While upgrading is the recommended method to mitigate CVE-2012-2313, restricting access to the affected ioctls can serve as a temporary workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203