GSD-2021-1000459

    Dashboard / Vulnerabilities / GSD-2021-1000459

    GSD-2021-1000459

    Published: 31 May 2021Last Modified: 22 Feb 2023

    Summary: mtd: require write permissions for locking and badblock ioctls

    Details: mtd: require write permissions for locking and badblock ioctls This is an automated ID intended to aid in discovery of potential security vulnerabilities. The actual impact and attack plausibility have not yet been proven. This ID is fixed in Linux Kernel version v4.19.191 by commit 75ed985bd6c8ac1d4e673e93ea9d96c9908c1d37, it was introduced in version v4.19.139 by commit ab1a602a9cea98aa37b2e6851b168d2a2633a58d. For more details please see the references link.

    References:

    Affected packages

    Package

    Name: Kernel

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- ab1a602a9cea98aa37b2e6851b168d2a2633a58d
    Fixed -None

    Affected versions

    v4.19.139
    v4.19.140
    v4.19.141
    v4.19.142
    v4.19.143
    v4.19.144
    v4.19.145
    v4.19.146
    v4.19.147
    v4.19.148
    v4.19.149
    v4.19.150
    v4.19.151
    v4.19.152
    v4.19.153
    v4.19.154
    v4.19.155
    v4.19.156
    v4.19.157
    v4.19.158
    v4.19.159
    v4.19.160
    v4.19.161
    v4.19.162
    v4.19.163
    v4.19.164
    v4.19.165
    v4.19.166
    v4.19.167
    v4.19.168
    v4.19.169
    v4.19.170
    v4.19.171
    v4.19.172
    v4.19.173
    v4.19.174
    v4.19.175
    v4.19.176
    v4.19.177
    v4.19.178
    v4.19.179
    v4.19.180
    v4.19.181
    v4.19.182
    v4.19.183
    v4.19.184
    v4.19.185
    v4.19.186
    v4.19.187
    v4.19.188
    v4.19.189
    v4.19.190

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2021-1000459 | CVE-DB