|Description||The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 18.104.22.168 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an "inverted logic" issue.|
|Source||CVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|References||DSA-1749-1, DSA-1787-1, DSA-1794-1|
|NVD severity||low (attack range: local)|
The information below is based on the following data on fixed versions.