CVE-2022-41973
29.10.2022, 18:15
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| opensvc | multipath-tools | 0.7.7 ≤ 𝑥 < 0.9.2 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| device-mapper-multipath |
| ||||||||||||
| device-mapper-multipath-devel |
| ||||||||||||
| device-mapper-multipath-libs |
| ||||||||||||
| kpartx |
| ||||||||||||
| libdmmp |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| device-mapper-multipath |
| ||
| device-mapper-multipath-debuginfo |
| ||
| device-mapper-multipath-debugsource |
| ||
| device-mapper-multipath-devel |
| ||
| device-mapper-multipath-libs |
| ||
| device-mapper-multipath-libs-debuginfo |
| ||
| kpartx |
| ||
| kpartx-debuginfo |
| ||
| libdmmp |
| ||
| libdmmp-debuginfo |
| ||
| libdmmp-devel |
|
References