Unrated severityNVD Advisory· Published Oct 29, 2022· Updated Aug 3, 2024
CVE-2022-41974
CVE-2022-41974
Description
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
43- multipath-tools/multipath-toolsdescription
- Range: >=0.7.0, <0.9.2
- osv-coords41 versionspkg:rpm/almalinux/device-mapper-multipathpkg:rpm/almalinux/device-mapper-multipath-develpkg:rpm/almalinux/device-mapper-multipath-libspkg:rpm/almalinux/kpartxpkg:rpm/almalinux/libdmmppkg:rpm/opensuse/multipath-tools&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/multipath-tools&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/multipath-tools&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/suse/multipath-tools&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/multipath-tools&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/multipath-tools&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/multipath-tools&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/multipath-tools&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/multipath-tools&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/multipath-tools&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 0.8.7-7.el9_0.1+ 40 more
- (no CPE)range: < 0.8.7-7.el9_0.1
- (no CPE)range: < 0.8.7-7.el9_0.1
- (no CPE)range: < 0.8.7-7.el9_0.1
- (no CPE)range: < 0.8.7-7.el9_0.1
- (no CPE)range: < 0.8.4-22.el8_6.2
- (no CPE)range: < 0.8.5+126+suse.8ce8da5-150300.2.14.1
- (no CPE)range: < 0.9.0+62+suse.3e048d4-150400.4.7.1
- (no CPE)range: < 0.8.5+126+suse.8ce8da5-150300.2.14.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-150100.3.20.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-150100.3.20.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-150100.3.20.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.7.3+173+suse.7dd1b01-150000.3.29.1
- (no CPE)range: < 0.7.3+173+suse.7dd1b01-150000.3.29.1
- (no CPE)range: < 0.8.5+126+suse.8ce8da5-150300.2.14.1
- (no CPE)range: < 0.8.5+126+suse.8ce8da5-150300.2.14.1
- (no CPE)range: < 0.9.0+62+suse.3e048d4-150400.4.7.1
- (no CPE)range: < 0.8.5+126+suse.8ce8da5-150300.2.14.1
- (no CPE)range: < 0.9.0+62+suse.3e048d4-150400.4.7.1
- (no CPE)range: < 0.6.2+suse20221017.514d453-71.26.1
- (no CPE)range: < 0.7.1+125+suse.c18e287-2.23.1
- (no CPE)range: < 0.7.3+177+suse.b16d5dc-2.23.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-3.14.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-150100.3.20.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-150100.3.20.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.7.3+173+suse.7dd1b01-150000.3.29.1
- (no CPE)range: < 0.7.3+177+suse.b16d5dc-2.23.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-3.14.1
- (no CPE)range: < 0.7.3+173+suse.7dd1b01-150000.3.29.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-150100.3.20.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.7.9+232+suse.cbc3754-3.14.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.8.2+182.6d41865-150200.4.14.1
- (no CPE)range: < 0.7.3+177+suse.b16d5dc-2.23.1
- (no CPE)range: < 0.7.3+177+suse.b16d5dc-2.23.1
Patches
Vulnerability mechanics
References
13- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QIGZM5NOOMFDCITOLQEJNNX5SCRQLQVV/mitrevendor-advisory
- security.gentoo.org/glsa/202311-06mitrevendor-advisory
- www.debian.org/security/2023/dsa-5366mitrevendor-advisory
- seclists.org/fulldisclosure/2022/Dec/4mitremailing-list
- seclists.org/fulldisclosure/2022/Oct/25mitremailing-list
- www.openwall.com/lists/oss-security/2022/11/30/2mitremailing-list
- lists.debian.org/debian-lts-announce/2022/12/msg00037.htmlmitremailing-list
- packetstormsecurity.com/files/169611/Leeloo-Multipath-Authorization-Bypass-Symlink-Attack.htmlmitre
- packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlmitre
- www.openwall.com/lists/oss-security/2022/10/24/2mitre
- bugzilla.suse.com/show_bug.cgimitre
- github.com/opensvc/multipath-tools/releases/tag/0.9.2mitre
- www.qualys.com/2022/10/24/leeloo-multipath/leeloo-multipath.txtmitre
News mentions
0No linked articles in our index yet.