Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-7928

Опубликовано: 17 нояб. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-7928: device-mapper-multipath security update (IMPORTANT)

[0.8.4-28.1]

  • Add 0111-multipathd-ignore-duplicated-multipathd-command-keys.patch
  • Resolves: bz #2133995

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

device-mapper-multipath

0.8.4-28.el8_7.1

device-mapper-multipath-devel

0.8.4-28.el8_7.1

device-mapper-multipath-libs

0.8.4-28.el8_7.1

kpartx

0.8.4-28.el8_7.1

libdmmp

0.8.4-28.el8_7.1

Oracle Linux x86_64

device-mapper-multipath

0.8.4-28.el8_7.1

device-mapper-multipath-devel

0.8.4-28.el8_7.1

device-mapper-multipath-libs

0.8.4-28.el8_7.1

kpartx

0.8.4-28.el8_7.1

libdmmp

0.8.4-28.el8_7.1

Связанные CVE

Связанные уязвимости

CVSS3: 8.4
redhat
почти 3 года назад

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CVSS3: 7.8
nvd
больше 2 лет назад

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

rocky
больше 2 лет назад

Important: device-mapper-multipath security update

rocky
больше 2 лет назад

Important: device-mapper-multipath security update

CVSS3: 7.8
github
больше 2 лет назад

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.