CVE-2022-41973 is a local privilege escalation vulnerability affecting multipath-tools versions 0.7.7 through 0.9.1, including various Debian and Fedora distributions. It allows local users with access to /dev/shm to manipulate symlinks within multipathd, leading to controlled file writes outside the intended directory. This vulnerability has a CVSS score of 7.8 (HIGH), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, it has been publicly disclosed and discussed in security media, notably as part of a chain of vulnerabilities leading to root privileges, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.7.7, < 0.9.2CPE matchmatch criteria | cpe:2.3:a:opensvc:multipath-tools:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-41973
Nov 8, 2022device-mapper-multipath: multipathd: insecure handling of files in /dev/shm leading to symlink attack
Oct 24, 2022multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
Oct 11, 2022