What the vulnerability does

01Description

A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality.

Key dates

02Disclosure timeline

March 25, 2022 CVE published
August 2, 2024 Record updated