Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-41973

25
FAUCET Score

CVE-2022-41973 is a local privilege escalation vulnerability affecting multipath-tools versions 0.7.7 through 0.9.1, including various Debian and Fedora distributions. It allows local users with access to /dev/shm to manipulate symlinks within multipathd, leading to controlled file writes outside the intended directory. This vulnerability has a CVSS score of 7.8 (HIGH), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, it has been publicly disclosed and discussed in security media, notably as part of a chain of vulnerabilities leading to root privileges, though no public exploit code is currently available.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.7.7, < 0.9.2CPE matchmatch criteria
cpe:2.3:a:opensvc:multipath-tools:*:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
47.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 85th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 18559-16820Fixed in: 0.8.6-1
microsoftpatch availablevia msrc
Product: 18560-16823Fixed in: 0.8.6-4
microsoftpatch availablevia msrc
Product: cbl2 device-mapper-multipath 0.8.6-4 on CBL Mariner 2.0Fixed in: 0.8.6-4
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 0.8.6-4
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 0.8.6-4
microsoftpatch availablevia msrc
Product: cm1 device-mapper-multipath 0.8.6-1 on CBL Mariner 1.0Fixed in: 0.8.6-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: device-mapper-multipath-0:0.8.4-37.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: device-mapper-multipath-0:0.8.4-22.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: device-mapper-multipath-0:0.8.7-20.el9
View patch

Vendor Advisories (3)

microsoft2022-Nov/CVE-2022-41973

CVE-2022-41973

Nov 8, 2022
redhatCVE-2022-41973Moderate

device-mapper-multipath: multipathd: insecure handling of files in /dev/shm leading to symlink attack

Oct 24, 2022
microsoft2022-Oct/CVE-2022-41973Important

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.

Oct 11, 2022

References

packetstormsecurity.com / files/169611/Leeloo-Multipath-Authorization-Bypass-Symlink-Attack.html
ExploitMailing ListThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.html
ExploitThird Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue TrackingThird Party Advisory
seclists.org / fulldisclosure/2022/Dec/4
ExploitThird Party Advisory
seclists.org / fulldisclosure/2022/Oct/25
ExploitMailing ListThird Party Advisory
github.com / opensvc/multipath-tools/releases/tag/0.9.2
Release NotesThird Party Advisory
lists.debian.org / debian-lts-announce/2022/12/msg00037.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QIGZM5NOOMFDCITOLQEJNNX5SCRQLQVV
security.gentoo.org / glsa/202311-06
debian.org / security/2023/dsa-5366
qualys.com / 2022/10/24/leeloo-multipath/leeloo-multipath.txt
ExploitThird Party Advisory
openwall.com / lists/oss-security/2022/10/24/2
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/11/30/2
ExploitThird Party Advisory