Описание
A flaw was found in multipathd. A local attacker with access to the multipathd UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the multipathd listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Отчет
A local denial of service vulnerability exists in multipathd where a local attacker with access to the UNIX control socket can block the IPC listener thread. This can lead to legitimate IPC operations hanging or timing out. This issue does not result in privilege escalation, code execution, or direct confidentiality or integrity impact, but it is practically reachable in default local IPC exposure scenarios.
Меры по смягчению последствий
To mitigate this issue, implement strict local access controls on systems running multipathd. This limits the ability of unprivileged users to interact with the multipathd IPC socket, thereby preventing exploitation of the world-writable control socket. Ensure that only trusted administrators have local access to the system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | device-mapper-multipath | Fix deferred | ||
| Red Hat Enterprise Linux 6 | device-mapper-multipath | Out of support scope | ||
| Red Hat Enterprise Linux 7 | device-mapper-multipath | Fix deferred | ||
| Red Hat Enterprise Linux 8 | device-mapper-multipath | Fix deferred | ||
| Red Hat Enterprise Linux 9 | device-mapper-multipath | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
A flaw was found in `multipathd`. A local attacker with access to the ...
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
EPSS
6.2 Medium
CVSS3