CVE-2012-2313: Linux Kernel
Low severity, CVSS 1.2. EPSS: 0.6% chance of exploitation in the next 30 days.
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
Affected products
- Linux Linux Kernel: up to and including 3.3.6; version 3.3 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; …
- Novell Suse Linux Enterprise Server: version 10.0 only
- Red Hat Enterprise Linux: version 5 only
- Red Hat Enterprise Linux Desktop: version 5.0 only
- Red Hat Enterprise Linux Eus: version 5.6.z only
- Red Hat Enterprise Linux Long Life: version 5.6 only
- Red Hat Enterprise Linux Server Aus: version 6.2 only
- Red Hat Enterprise Linux Server Eus: version 6.1.z only; version 6.2.z only
Published 2012-06-13. Last modified 2026-06-16.