CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Affected Products (NVD)
VendorProductVersion
redhatdevice-mapper-multipath
-
redhatenterprise_linux
8.7
redhatenterprise_linux
9.1
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
device-mapper-multipath
RHEL 9
0:0.8.7-12.el9_1.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
device-mapper-multipath
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
device-mapper-multipath-debuginfo
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
device-mapper-multipath-debugsource
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
device-mapper-multipath-devel
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
device-mapper-multipath-libs
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
device-mapper-multipath-libs-debuginfo
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
kpartx
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
kpartx-debuginfo
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
libdmmp
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
libdmmp-debuginfo
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed
libdmmp-devel
Amazon Linux 2023
0:0.8.7-16.amzn2023.0.1
fixed