CVE-2012-4542: Linux Kernel

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

Affected products

  • Linux Linux Kernel: up to and including 3.8.0; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; …

Published 2013-02-28. Last modified 2026-06-16.