Opensvc maintains a narrowly scoped, specialized portfolio centered on the multipath-tools storage management utility, which is embedded across Linux systems managing redundant storage paths and device failover. The durable vulnerability signal reflects the tool's privileged role in storage I/O and recurs through weakness classes including improper link resolution before file access and improper privilege management, indicating structural challenges in safely handling filesystem symlinks and access controls within a root-context daemon. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensvc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41974HIGH multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UN | Oct 29, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-41973HIGH multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can | Oct 29, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensvc.
Media articles that mention a CVE ID that affects a product developed by Opensvc — matched by CVE ID, not by vendor name.