Back

LOW

security flaw

Published Feb 6, 2005

Description

Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 6, 2005
Updated Aug 7, 2024
Reserved Jan 28, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 7, 2005