Описание
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
Отчет
This issue only affected Red Hat Enterprise Linux 8.7 and Red Hat Enterprise Linux 9.1, which introduced this regression via the following errata: https://access.redhat.com/errata/RHBA-2022:7714 (Red Hat Enterprise Linux 8.7) https://access.redhat.com/errata/RHBA-2022:8313 (Red Hat Enterprise Linux 9.1) These errata provided updates for device-mapper-multipath packages, but did not include fixes for CVE-2022-41974. This issue did not affect Red Hat Enterprise Linux 8.6 or earlier, and Red Hat Enterprise Linux 9.0, as previously released fixes for CVE-2022-41974 were not regressed in those versions. For more details about the original security issue CVE-2022-41974, refer to the CVE page: https://access.redhat.com/security/cve/CVE-2022-41974.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | device-mapper-multipath | Not affected | ||
Red Hat Enterprise Linux 7 | device-mapper-multipath | Not affected | ||
Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | ||
Red Hat Enterprise Linux 8 | device-mapper-multipath | Fixed | RHSA-2022:7928 | 14.11.2022 |
Red Hat Enterprise Linux 9 | device-mapper-multipath | Fixed | RHSA-2022:8453 | 15.11.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.4 High
CVSS3
Связанные уязвимости
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
ELSA-2022-8453: device-mapper-multipath security update (IMPORTANT)
EPSS
8.4 High
CVSS3