Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89329

Опубликовано: 11 сент. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in multipathd. A local attacker with access to the multipathd UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the multipathd listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.

Отчет

A local denial of service vulnerability exists in multipathd where a local attacker with access to the UNIX control socket can block the IPC listener thread. This can lead to legitimate IPC operations hanging or timing out. This issue does not result in privilege escalation, code execution, or direct confidentiality or integrity impact, but it is practically reachable in default local IPC exposure scenarios.

Меры по смягчению последствий

To mitigate this issue, implement strict local access controls on systems running multipathd. This limits the ability of unprivileged users to interact with the multipathd IPC socket, thereby preventing exploitation of the world-writable control socket. Ensure that only trusted administrators have local access to the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10device-mapper-multipathFix deferred
Red Hat Enterprise Linux 6device-mapper-multipathOut of support scope
Red Hat Enterprise Linux 7device-mapper-multipathFix deferred
Red Hat Enterprise Linux 8device-mapper-multipathFix deferred
Red Hat Enterprise Linux 9device-mapper-multipathFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1322
https://bugzilla.redhat.com/show_bug.cgi?id=2470013device-mapper-multipath: Local Denial of Service via Blocking IPC Send Operations

EPSS

Процентиль: 2%
0.00117
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
2 дня назад

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.

CVSS3: 6.2
nvd
4 дня назад

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.

CVSS3: 6.2
debian
4 дня назад

A flaw was found in `multipathd`. A local attacker with access to the ...

CVSS3: 6.2
github
4 дня назад

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.

EPSS

Процентиль: 2%
0.00117
Низкий

6.2 Medium

CVSS3