CVE-2013-6383

medium
Published 2013-11-27 · Modified 2026-04-29
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which allows local users to bypass intended access restrictions via a crafted ioctl call.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-6383

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/torvalds/linux/commit/f856567b930dfcdbc3323261bf77240ccdde01f5

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.11.8

OS impact

OSVersionStatusFixed in
linux linux-kernelaffected3.2.53
debian debianbookwormfixed3.11.8-1
debian debianbullseyefixed3.11.8-1
debian debianforkyfixed3.11.8-1
debian debiansidfixed3.11.8-1
debian debiantrixiefixed3.11.8-1

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.