Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors. NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel SDLA IOCTL未经授权的本地固件访问漏洞
Vulnerability Description
Linux kernel 2.6.11之前的2.6.x版本以及2.4.29之前的2.4.x版本中的wan/sdla.c,不要求SDLA的CAP_SYS_RAWIO固件升级,具有未知影响和本地攻击矢量。注意:进一步调查表明,由于此问题受CAP_NET_ADMIN的保护,所以它需要使用根特权;因此,即使能够很好地区分不同特权等级,此问题可能也不是漏洞。
CVSS Information
N/A
Vulnerability Type
N/A